End-to-End Transparent Transmission Encryption Method and Device
By introducing a transmission encryption gateway between communication devices, key negotiation and data encryption are implemented using the virtual IP address and IKEv2 protocol, the problem that traditional transmission encryption devices cannot achieve transparent transmission is solved, and efficient and unsensed data encryption is achieved.
Patent Information
- Application Number
- CN202210746315.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-06-28
AI Technical Summary
Existing transmission encryption devices cannot achieve true transparent transmission encryption in actual engineering applications. They need to occupy independent IP addresses, configure the IP addresses of the counterpart VPN devices, and usually need to change the network topology.
Two transmission encryption gateways are added between the source communication device and the destination communication device, and the local virtual IP addresses for external key negotiation communication are obtained, and the encrypted session stream is started using these virtual IP addresses, and the key negotiation session is performed based on the IKEv2 protocol to generate a secure association to realize encrypted data stream transmission.
It realizes transparent transmission and encryption of data without changing the user's original network and increasing the network burden, simplifying the project implementation process and being able to penetrate the existing network.
Smart Images

Figure CN115118503B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of network communication and data security, and particularly to an end-to-end transparent transmission encryption method and device. Background Art
[0002] With the rapid development of the Internet, more and more data is transmitted via the Internet. Therefore, data encryption has become particularly important. Existing data transmission encryption methods applicable to the Internet generally include: 1) Network layer transmission encryption, such as VPN devices / software based on the standard IPSEC protocol (or a custom encryption protocol at the network layer); 2) Application layer transmission encryption, such as transmission encryption devices based on the standard SSL / TLS protocol (or a custom encryption protocol at the application layer).
[0003] However, these traditional transmission encryption devices need to occupy independent IP addresses in actual engineering applications, configure the IP addresses of the peer VPN devices (for key negotiation), and usually also need to change the network topology (configure tunnel and routing related data). Therefore, true transparent transmission encryption cannot be achieved. Summary of the Invention
[0004] The present invention provides an end-to-end transparent transmission encryption method for data transmission between a source communication device and a destination communication device. The source communication device is connected to a first transmission encryption gateway, and the destination communication device is connected to a second transmission encryption gateway. The first transmission encryption gateway and the second transmission encryption gateway communicate via the Internet. The method includes the following steps:
[0005] Obtain the local virtual IP address of the first transmission encryption gateway for external key negotiation communication and the local virtual IP address of the second transmission encryption gateway for external key negotiation communication;
[0006] Based on the local virtual IP address of the first transmission encryption gateway and the local virtual IP address of the second transmission encryption gateway, initiate an encrypted session stream between the first transmission encryption gateway and the second transmission encryption gateway;
[0007] Conduct a key negotiation session between the first transmission encryption gateway and the second transmission encryption gateway based on the standard IKEv2 protocol to generate a security association;
[0008] Utilize the security association to perform encrypted data stream transmission between the source communication device and the destination communication device.
[0009] In the end-to-end transparent transmission encryption method provided by the present invention, the first transmission encryption gateway transparently forwards the packet flow between the first network interface and the second network interface of the first transmission encryption gateway based on the DPDK technology, and the local virtual IP address of the first transmission encryption gateway is the IP address of the source communication device; the second transmission encryption gateway transparently forwards the packet flow between the first network interface and the second network interface of the second transmission encryption gateway based on the DPDK technology, and the local virtual IP address of the second transmission encryption gateway is the IP address of the destination communication device.
[0010] In the end-to-end transparent transmission encryption method provided by the present invention, the steps of starting the encrypted session flow between the first transmission encryption gateway and the second transmission encryption gateway with the local virtual IP address of the first transmission encryption gateway and the local virtual IP address of the second transmission encryption gateway include:
[0011] Send a connection request packet from the source communication device to the first transmission encryption gateway;
[0012] The first transmission encryption gateway parses the connection request packet. When the source IP in the connection request packet is the local virtual IP address of the first transmission encryption gateway and includes the start packet parameter, start the key negotiation session and the encrypted data stream between the first transmission encryption gateway and the second transmission encryption gateway;
[0013] The second transmission encryption gateway parses the connection request packet. When the destination IP in the connection request packet is the local virtual IP address of the second transmission encryption gateway and includes the start packet parameter, start the key negotiation session and the encrypted data stream between the second transmission encryption gateway and the first transmission encryption gateway.
[0014] In the end-to-end transparent transmission encryption method provided by the present invention, the key negotiation communication between the first transmission encryption gateway and the second transmission encryption gateway is based on a quadruple UDP session, and the IKE packet is carried in the data field of UDP.
[0015] In the end-to-end transparent transmission encryption method provided by the present invention, the steps of transmitting the encrypted data stream between the source communication device and the destination communication device by using the security association include:
[0016] The first transmission encryption gateway parses the first packet from the source communication device. When the source IP and destination IP fields included in the first packet match the security association row, encrypt the data payload part of the first packet by using the encryption key of the security association to generate an encrypted data payload part;
[0017] Update the first message to a second message by using the encrypted payload part, and forward the second message to the second transport encryption gateway;
[0018] The second transport encryption gateway parses the second message. When the source IP and destination IP fields included in the second message match the security association line, decrypt the payload part of the second message by using the encryption key of the security association to generate plaintext;
[0019] Update the second message to a third message by using the plaintext and forward it to the destination communication device.
[0020] In the end-to-end transparent transport encryption method provided by the present invention, the step of updating the first message to a second message by using the encrypted payload part includes:
[0021] Calculate a digest for the encrypted payload part to generate a digest;
[0022] Use the encrypted payload part and the digest as the payload part of the second message;
[0023] Modify the protocol type of the IP header of the second message to a new TCP / UDP protocol value;
[0024] Recalculate the length field and checksum of the TCP / UDP header of the second message, as well as the message length and checksum of the IP header.
[0025] In the end-to-end transparent transport encryption method provided by the present invention, the plaintext includes the payload part of the first message and the digest. The step of updating the second message to a third message by using the plaintext includes:
[0026] Perform verification by using the digest. If the verification passes, use the payload part of the first message as the payload part of the third message;
[0027] Modify the protocol type of the IP header of the third message to the original TCP / UDP protocol value;
[0028] Recalculate the length field and checksum of the TCP / UDP header of the third message, as well as the message length and checksum of the IP header
[0029] In addition, to achieve the above object, the present invention also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the end-to-end transparent transport encryption method as described above are implemented.
[0030] In addition, to achieve the above object, the present invention further provides an end-to-end transparent transmission encryption device, which is characterized in that it includes a processor and a memory, the memory stores a computer program, and when the computer program is executed by the processor, the steps of the above-mentioned end-to-end transparent transmission encryption method are implemented.
[0031] The end-to-end transparent transmission encryption method provided by the present invention has the following beneficial effects: For the end-to-end transparent transmission encryption method provided by the present invention, two transmission encryption gateways are added between the source communication device and the destination communication device. First, obtain the local virtual IP addresses for external key negotiation communication for these two transmission encryption gateways respectively; then these two transmission encryption gateways use their respective local virtual IP addresses to initiate an encrypted session flow between them and conduct a key negotiation session based on the IKEv2 protocol; subsequently, use the generated security association to implement the encrypted data stream transmission between the source communication device and the destination communication device; thus, the transmission encryption gateway itself does not need to be configured with an IP address and related data, is imperceptible to users, does not change the original network of users, does not increase the network burden, can penetrate the existing network, and greatly simplifies the engineering implementation of transparent transmission encryption. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on the provided drawings:
[0033] Figure 1 The figure shows a schematic diagram of an application scenario of the end-to-end transparent transmission encryption method provided by an embodiment of the present invention;
[0034] Figure 2 The figure shows a schematic diagram of the process of the end-to-end transparent transmission encryption method provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0035] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. The typical embodiments of the present invention are shown in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, the purpose of providing these embodiments is to make the disclosure of the present invention more thorough and comprehensive.
[0036] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this invention belongs. The terms used in the description of the present invention herein are for the purpose of describing specific embodiments only and are not intended to limit the present invention.
[0037] The general idea of the present invention is as follows: For traditional transmission encryption devices, which cannot achieve true transparent transmission encryption in actual engineering applications, require an independent IP address, need to configure the IP address of the peer VPN device (for key negotiation), and usually also need to change the network topology (configure tunnel and routing related data). Two transmission encryption gateways are added between the source communication device and the destination communication device. First, obtain the local virtual IP addresses for external key negotiation communication for these two transmission encryption gateways respectively; then these two transmission encryption gateways start the encrypted session flow between them using their respective local virtual IP addresses and conduct a key negotiation session based on the IKEv2 protocol; subsequently, use the generated security association to achieve encrypted data stream transmission between the source communication device and the destination communication device. Thus, the transmission encryption gateway itself does not need to configure IP addresses and related data, is imperceptible to users, does not change the original network of users, does not increase the network burden, can penetrate the existing network, and greatly simplifies the engineering implementation of transparent transmission encryption.
[0038] To better understand the above technical solution, the above technical solution will be described in detail below in conjunction with the accompanying drawings of the specification and specific implementation manners. It should be understood that the embodiments of the present invention and the specific features in the embodiments are detailed descriptions of the technical solution of the present application, rather than limitations on the technical solution of the present application. Without conflict, the technical features in the embodiments of the present invention and the embodiments can be combined with each other.
[0039] Figure 1 Shown is a schematic diagram of an application scenario of an end-to-end transparent transmission encryption method provided by an embodiment of the present invention. As Figure 1 shown, host A and host B communicate data through the Internet (host A and host B can include IP terminals or communication devices such as a PC, a server, a gateway, a firewall, a router, etc. with at least one public network independent IP address). Without adding any IP addresses and without changing any data configurations, a transmission encryption gateway A is connected in series between host A and the Internet (its network interfaces A1 and A2 are respectively connected to host A and the Internet), and a transmission encryption gateway B is connected in series between host B and the Internet (its network interfaces B1 and B2 are respectively connected to router B and the Internet). After the transformation, the data communication between host A and host B will have the function of transparent transmission encryption.
[0040] Figure 2The following is a schematic flow chart of an end-to-end transparent transmission encryption method provided by an embodiment of the present invention. In this embodiment, the data transmission from host A to host B is taken as an example for illustration. Therefore, host A is used as the source communication device, host B is used as the destination communication device, gateway A is used as the first transmission encryption gateway, and gateway B is used as the second transmission encryption gateway. As Figure 2 shown, the end-to-end transparent transmission encryption method provided by the present invention includes:
[0041] Step S1: Obtain the local virtual IP address of the first transmission encryption gateway for external key negotiation communication and the local virtual IP address of the second transmission encryption gateway for external key negotiation communication.
[0042] Specifically, in an embodiment of the present invention, the local virtual IP address refers to the IP address of the gateway during external key negotiation communication. In the initial startup situation, the first transmission encryption gateway transparently forwards all packet flows between its two network interfaces (i.e., network interface A1 and A2) based on the DPDK (Data Plane Development Kit) technology. At the same time, it parses all ARP response packets passing through network interface A1, and obtains the IP address of the directly connected source communication device as the local virtual IP address of the first transmission encryption gateway for external key negotiation communication, that is, VIP_A. Similarly, the second transmission encryption gateway also transparently forwards all packet flows between network interfaces B1 and B2 based on the DPDK technology, and obtains the IP address of the directly connected host B (i.e., the destination communication device) by parsing the ARP response packets of network interface B1 as the local virtual IP of the second transmission encryption gateway, that is, VIP_B. By transparently forwarding the packet flows between the two network interfaces of the transmission encryption gateway based on the DPDK technology, and then parsing the response packets to use the obtained IP address of the directly connected host as the local virtual IP address of the transmission encryption gateway for external key communication negotiation, there is no need to configure an IP address for the transmission encryption device itself.
[0043] Step S2: Based on the local virtual IP address of the first transmission encryption gateway and the local virtual IP address of the second transmission encryption gateway, start the encrypted session flow between the first transmission encryption gateway and the second transmission encryption gateway.
[0044] Specifically, in an embodiment of the present invention, a ping command for pinging the IP address of the destination communication device is sent on the source communication device. At the same time, the specified packet length = PL01. Here, PL01 is the specified length value of the ping packet used to initiate the encrypted session flow between gateway A and gateway B, with a default value of 800 and a configurable range of 200 to 1500; PL02 is the specified length value of the ping packet used to close the encrypted session flow between gateway A and gateway B, with a default value of 880 and a configurable range of 200 to 1500 (PL02 and PL02 cannot be repeated). Then, gateway A receives this ping command packet through network port A1. If it analyzes that the source IP of the ping packet = VIP_A and the packet length = PL01, it determines that the source communication device has initiated the transparent transmission encryption instruction between gateway A and gateway B, and initiates a quadruple UDP session based on "source VIP_A:VPT_A + destination VIP_B:VPT_B" to conduct the key negotiation session and encrypted data stream between gateway A and B; this ping packet is transmitted through the Internet to gateway B. Gateway B analyzes that the destination IP of the ping packet = VIP_B and the packet length = PL01, and initiates a quadruple UDP session based on "source VIP_B:VPT_B + destination VIP_A:VPT_A" to conduct the key negotiation session and encrypted data stream between gateway B and A. Among them, the key negotiation communication between gateway A and B is based on the UDP protocol. Therefore, the corresponding communication ports are respectively defined as VPT_A and VPT_B, with default values both being 60000 and a configurable range of 10000 to 64000. Therefore, step S2 includes:
[0045] Send a connection request packet from the source communication device to the first transmission encryption gateway;
[0046] The first transmission encryption gateway parses the connection request packet. When the source IP of the connection request packet is the local virtual IP address of the first transmission encryption gateway and includes the start packet parameter, it initiates the key negotiation session and encrypted data stream between the first transmission encryption gateway and the second transmission encryption gateway;
[0047] The second transmission encryption gateway parses the connection request packet. When the destination IP of the connection request packet is the local virtual IP address of the second transmission encryption gateway and includes the start packet parameter, it initiates the key negotiation session and encrypted data stream between the second transmission encryption gateway and the first transmission encryption gateway.
[0048] Step S3, conduct a key negotiation session based on the standard IKEv2 protocol between the first transmission encryption gateway and the second transmission encryption gateway to generate a security association.
[0049] Specifically, in an embodiment of the present invention, the key negotiation communication between the first transmission encryption gateway and the second transmission encryption gateway is based on the quadruple UDP session of "VIP_A:VPT_A + VIP_B:VPT_B", and the IKE message is directly carried through the data field of UDP. A security association (SA), which is used to record the policies and policy parameters of each IP security path, is the basis of IPsec and an agreement established between two communicating parties, determining the protocol, transcoding method, key, and key validity period for protecting data packets; IKEv2 is the abbreviation of the Internet Key Exchange Version 2 key management protocol, which is used to exchange the Internet keys of IPsec. In this embodiment, the service process of key negotiation follows the standard IKEv2, and the encryption key negotiation and update are performed with reference to the IKE protocol. The symmetric algorithm in the encryption suite selects the national cipher SM4-CBC, the digest algorithm selects the national cipher SM3, the asymmetric algorithm selects SM2, and the key update period is defaulted to 30 minutes.
[0050] Step S4: Using the security association, encrypted data stream transmission is performed between the source communication device and the destination communication device.
[0051] Specifically, in an embodiment of the present invention, considering that the main service data is carried through TCP / UDP, therefore, the first transmission encryption gateway and the second transmission encryption gateway only encrypt and decrypt TCP / UDP packets, and other protocol packets such as ARP, ICMP, BGP, RIP, IGRP, etc. will be directly passed through to achieve the purpose of transparent encryption (without affecting the network layout). During the process of data transmission from the source communication device to the destination communication device, the first transmission encryption gateway is used to encrypt the data, and the second transmission encryption gateway is used to decrypt the data.
[0052] Furthermore, in an embodiment of the present invention, the data encryption process of the first transmission encryption gateway is as follows:
[0053] The first transmission encryption gateway parses the first packet from the source communication device. When the source IP and destination IP fields included in the first packet match the security association line, the encryption key of the security association is used to encrypt the data payload part of the first packet to generate an encrypted data payload part;
[0054] For example, the packet payload text00 carried by the host A based on TCP / UDP enters the gateway A through the network interface A1. The gateway A matches the "source IP, destination IP" fields of the IP packet header with the "VIP_A, VIP_B" of the session SA. If a match is found (otherwise, it is directly passed through to the network interface A2), the encryption key pair corresponding to the SA is found to perform SM4-CBC encryption on the data payload part text00 to generate the ciphertext ciph00;
[0055] The first packet is updated to the second packet by using the encrypted data payload part, and the second packet is forwarded to the second transport encryption gateway; specifically, it includes calculating a digest for the encrypted data payload part to generate a digest; using the encrypted data payload part and the digest as the data payload part of the second packet; modifying the protocol type of the IP packet header of the second packet to a new TCP / UDP protocol value; recalculating the length field and checksum of the TCP / UDP packet header of the second packet, as well as the packet length and checksum of the IP packet header;
[0056] For example, in an embodiment of the present invention, after generating the ciphertext ciph00, a digest is calculated for the ciphertext to generate a digest h00; the original data payload part text00 is replaced with the encrypted ciph00 + h00, the protocol type of the IP header is modified to a new TCP / UDP protocol value (i.e., IPPROTO_TCP => IPPROTO_TCPN, IPPROTO_UDP => IPPROTO_UDPN), the length field and checksum of the TCP / UDP packet header are recalculated, the packet length and checksum of the IP packet header are recalculated, and the encrypted and updated packet is sent to the Internet through the network interface A2.
[0057] Further, in an embodiment of the present invention, the data decryption process of the second transport encryption gateway is as follows:
[0058] The second transport encryption gateway parses the second packet. If the protocol type of the IP packet header in the second packet is the new TCP / UDP protocol value, it determines that the packet is an encrypted packet (otherwise, it is directly passed through), and uses the source IP and destination IP fields included in the packet to match the encryption key of the security association to decrypt the data payload part of the second packet to generate the plaintext;
[0059] For example, the encrypted packet "ciph00 + h00" is forwarded to the network interface B2 of the gateway B through the Internet. The gateway B determines that the packet is an encrypted packet (otherwise, it is directly passed through) because the protocol type of the IP packet header is the new TCP / UDP protocol value. It matches the "source IP, destination IP" fields with the session SA "VIP_A, VIP_B" to find the encryption key pair corresponding to the SA and perform SM4-CBC decryption on the encrypted data payload part "ciph00 + h00" to generate the plaintext ciph00;
[0060] Then, update the second message to a third message using plaintext update and forward it to the destination communication device; specifically including: performing verification using the digest, and if the verification passes, using the data payload part of the first message as the data payload part of the third message; modifying the protocol type of the IP header of the third message to the original TCP / UDP protocol value; recalculating the length field and checksum of the TCP / UDP header of the third message, as well as the message length and checksum of the IP header.
[0061] For example, verify the decrypted digest h00. If there is an error, discard the data; if the verification fails, restore the protocol type of the IP header to the original TCP / UDP protocol type (i.e., IPPROTO_TCPN => IPPROTO_TCP, IPPROTO_UDPN => IPPROTO_UDP), recalculate the length field and checksum of the TCP / UDP header, recalculate the message length and checksum of the IP header, and send the decrypted and updated plaintext message to the host B through network interface B1.
[0062] An embodiment of the present invention further provides an end-to-end transparent transmission encryption device, which may include:
[0063] A memory for storing computer programs;
[0064] A processor, when executing the computer program stored in the above memory, can implement the following steps:
[0065] Obtain the local virtual IP address of the first transmission encryption gateway for external key negotiation communication and the local virtual IP address of the second transmission encryption gateway for external key negotiation communication; based on the local virtual IP address of the first transmission encryption gateway and the local virtual IP address of the second transmission encryption gateway, start an encrypted session flow between the first transmission encryption gateway and the second transmission encryption gateway; perform a key negotiation session between the first transmission encryption gateway and the second transmission encryption gateway based on the standard IKEv2 protocol to generate a security association; use the security association to perform encrypted data stream transmission between the source communication device and the destination communication device.
[0066] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the following steps can be implemented;
[0067] Obtain the local virtual IP address of the first transport encryption gateway for external key negotiation communication and the local virtual IP address of the second transport encryption gateway for external key negotiation communication; based on the local virtual IP address of the first transport encryption gateway and the local virtual IP address of the second transport encryption gateway, start the encrypted session flow between the first transport encryption gateway and the second transport encryption gateway; conduct a key negotiation session between the first transport encryption gateway and the second transport encryption gateway based on the standard IKEv2 protocol to generate a security association; utilize the security association to perform encrypted data stream transmission between the source communication device and the destination communication device.
[0068] The computer-readable storage medium may include: various media such as USB flash drives, external hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.
[0069] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present invention may be practiced without these specific details. In some instances, well-known methods, structures, and technologies have not been shown in detail so as not to obscure the understanding of this specification.
[0070] Similarly, it should be understood that, in order to streamline the present disclosure and assist in understanding one or more of the various inventive aspects, in the foregoing description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all the features of the single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into the detailed description, with each claim standing on its own as a separate embodiment of the present invention.
[0071] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and arranged in one or more devices different from the embodiments. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be adopted to combine all the features disclosed in this specification (including the accompanying claims, abstract and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise explicitly stated, each feature disclosed in this specification (including the accompanying claims, abstract and drawings) can be replaced by an alternative feature providing the same, equivalent or similar purpose.
[0072] In addition, those skilled in the art can understand that although some of the embodiments herein include certain features included in other embodiments rather than other features, the combination of the features of different embodiments means that it is within the scope of the present invention and forms different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.
[0073] Each component embodiment of the present invention can be implemented in hardware, or in software modules running on one or more processors, or in a combination thereof. Those skilled in the art should understand that a microprocessor or a digital signal processor (DSP) can be used in practice to implement some or all of the functions of some or all of the components according to the embodiments of the present invention. The present invention can also be implemented as a device or apparatus program (such as a computer program and a computer program product) for executing part or all of the methods described herein. Such a program implementing the present invention can be stored on a computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, or provided on a carrier signal, or provided in any other form.
[0074] It should be noted that the above embodiments illustrate the present invention rather than limit the present invention, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present invention can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In the unit claims listing several devices, several of these devices can be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names.
Claims
1. An end-to-end transparent transmission encryption method for data transmission between a source communication device and a destination communication device. The source communication device is connected to a first transmission encryption gateway, and the destination communication device is connected to a second transmission encryption gateway. The first transmission encryption gateway and the second transmission encryption gateway communicate through the Internet. Characterized in that, The method includes the following steps: Obtain the local virtual IP address of the first transmission encryption gateway for external key negotiation communication and the local virtual IP address of the second transmission encryption gateway for external key negotiation communication; Based on the local virtual IP address of the first transmission encryption gateway and the local virtual IP address of the second transmission encryption gateway, start the encrypted session flow between the first transmission encryption gateway and the second transmission encryption gateway; Conduct a key negotiation session between the first transmission encryption gateway and the second transmission encryption gateway based on the standard IKEv2 protocol to generate a security association; Utilize the security association to perform encrypted data stream transmission between the source communication device and the destination communication device; The first transmission encryption gateway transparently forwards the packet flow between the first network interface and the second network interface of the first transmission encryption gateway based on the DPDK technology. The local virtual IP address of the first transmission encryption gateway is the IP address of the source communication device; The second transmission encryption gateway transparently forwards the packet flow between the first network interface and the second network interface of the second transmission encryption gateway based on the DPDK technology. The local virtual IP address of the second transmission encryption gateway is the IP address of the destination communication device.
2. The end-to-end transparent transmission encryption method according to claim 1, Characterized in that, The step of starting the encrypted session flow between the first transmission encryption gateway and the second transmission encryption gateway based on the local virtual IP address of the first transmission encryption gateway and the local virtual IP address of the second transmission encryption gateway includes: Send a connection request message to the first transmission encryption gateway on the source communication device; The first transmission encryption gateway parses the connection request message. When the source IP of the connection request message is the local virtual IP address of the first transmission encryption gateway and includes the start message parameter, start the key negotiation session and encrypted data stream between the first transmission encryption gateway and the second transmission encryption gateway; The second transmission encryption gateway parses the connection request message. When the destination IP of the connection request message is the local virtual IP address of the second transmission encryption gateway and includes the start message parameter, start the key negotiation session and encrypted data stream between the second transmission encryption gateway and the first transmission encryption gateway.
3. The end-to-end transparent transmission encryption method according to claim 2, Characterized in that, The key negotiation communication between the first transmission encryption gateway and the second transmission encryption gateway is based on a quadruple UDP session, and the IKE message is carried in the data field of UDP.
4. The end-to-end transparent transmission encryption method according to claim 3, Characterized in that, The steps of performing encrypted data stream transmission between the source communication device and the destination communication device by using the security association include: The first transmission encryption gateway parses the first packet from the source communication device. When the source IP and destination IP fields included in the first packet match the security association, the encryption key of the security association is used to encrypt the data payload part of the first packet to generate an encrypted data payload part; The first packet is updated to a second packet by using the encrypted data payload part, and the second packet is forwarded to the second transmission encryption gateway; The second transmission encryption gateway parses the second packet. When the source IP and destination IP fields included in the second packet match the security association, the encryption key of the security association is used to decrypt the data payload part of the second packet to generate plaintext; The second packet is updated to a third packet by using the plaintext and forwarded to the destination communication device.
5. The end-to-end transparent transmission encryption method according to claim 4, wherein, the step of updating the first packet to the second packet by using the encrypted data payload part includes: calculating a digest of the encrypted data payload part to generate a digest; using the encrypted data payload part and the digest as the data payload part of the second packet; modifying the protocol type of the IP header of the second packet to a new TCP / UDP protocol value; recalculating the length field and checksum of the TCP / UDP header of the second packet, as well as the packet length and checksum of the IP header.
6. The end-to-end transparent transmission encryption method according to claim 5, wherein, the plaintext includes the data payload part of the first packet and the digest. The step of updating the second packet to the third packet by using the plaintext includes: performing verification by using the digest. If the verification passes, using the data payload part of the first packet as the data payload part of the third packet; modifying the protocol type of the IP header of the third packet to the original TCP / UDP protocol value; recalculating the length field and checksum of the TCP / UDP header of the third packet, as well as the packet length and checksum of the IP header.
7. A computer-readable storage medium, wherein, the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the end-to-end transparent transmission encryption method according to any one of claims 1 to 6 are implemented.
8. An end-to-end transparent transmission encryption device, wherein, it includes a processor and a memory. The memory stores a computer program, and when the computer program is executed by the processor, the steps of the end-to-end transparent transmission encryption method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Method and system for achieving communication security protection
CN103259769A