Data encryption method and system based on virtual routing forwarding technology
By setting up an encryption machine within the virtual routing forwarding area, the routing and decryption of encrypted messages are realized, which solves the impact and cost issues of network layer encryption device deployment on network architecture, meets business needs, and maintains network stability.
Patent Information
- Application Number
- CN202211197807.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-29
- Publication Date
- 2026-02-17
- Estimated Expiration
- 2042-09-29
AI Technical Summary
In existing technologies, the deployment method of network layer encryption devices affects the network architecture, increases costs and complexity, and cannot meet the encryption and decryption requirements of some business data streams.
By employing virtual routing and forwarding technology, encryption machines are set up within the virtual routing and forwarding areas of the first and second office areas to enable the routing and decryption of encrypted messages, thus meeting the encryption and decryption needs between different office areas.
It reduces the deployment cost of encryption devices, maintains the stability of high-speed and high-availability networks, avoids the risk of business interruption due to encryption machine failure, and reduces the impact on existing networks.
Smart Images

Figure CN115632829B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of virtual routing and forwarding, and in particular to a data encryption method and system based on virtual routing and forwarding. BACKGROUND
[0002] Virtual Routing and Forwarding (VRF) is a virtualization technology, which can be used to build multiple VRF areas in a global device / network, and each area has independent interfaces, routing tables and protocols.
[0003] In order to meet the security requirements of partial key business data transmission, network layer encryption devices need to be deployed to encrypt and decrypt key business communication data streams in different regions and areas in real time. The encryption device is deployed in a transparent mode or a routing mode to realize point-to-point encryption of key business data streams through the encryption device and meet the encryption and decryption needs of the data stream.
[0004] Regarding the transparent mode, the encryption machine needs to be connected in series in the network, which changes the network architecture. In addition, the network environment is a gigabit high-availability network, and the encryption device needs to be a gigabit device and configured with two high-availability devices to ensure that the overall network quality does not decrease. For smaller business data stream encryption needs, a hundred megabit or gigabit encryption machine can meet the business needs, and configuring a gigabit encryption machine will cause a large cost expenditure.
[0005] Regarding the routing mode, the encryption machine can be connected in series in the network or hung on the network device. If connected in series in the network, the problem is the same as above; if hung on the network device, the network device routing strategy needs to be adjusted. In addition, the encryption machine in the routing mode configures a business IP address, which will perform address translation on the business address, and the existing business data stream needs to be modified, but some specific business data streams do not support address translation, such as video conference data streams. Therefore, deploying the encryption machine in the routing mode changes the network architecture, increases the complexity of the network, affects the existing business, and cannot meet the encryption and decryption needs of partial data streams.
[0006] In summary, in order to realize the encryption and decryption of partial business data streams in the network, the network layer encryption device is deployed in a transparent mode, which has good compatibility, but the traditional series connection method deployed in the network has a certain impact on the network environment and is relatively high in cost. SUMMARY
[0007] In view of the problems in the prior art, the main purpose of the embodiments of the present application is to provide a data encryption method and system based on virtual routing and forwarding, which reduces the construction cost and meets the business needs.
[0008] To achieve the above object, the embodiment of the present application provides a data encryption method based on a virtual route forwarding technology, which comprises the following steps:
[0009] The business system in the first office area initiates a message request for requesting business data from the second office area, the encryptor in the first office area performs encryption processing on the message request to obtain an encrypted message, and the encryptor in the first office area sends the encrypted message to the global area; wherein the business system and the encryptor in the first office area are arranged in a virtual route forwarding area in the first office area;
[0010] The global area performs route flow conversion processing on the encrypted message and sends the encrypted message to the second office area;
[0011] The encryptor in the second office area performs decryption processing on the encrypted message to obtain the message request, and the business system in the second office area performs business processing by using the message request; wherein the encryptor and the business system in the second office area are arranged in a virtual route forwarding area in the second office area.
[0012] Optionally, in the embodiment of the present application, the business system in the first office area initiating the message request for requesting business data from the second office area comprises the following steps:
[0013] The business system in the first office area initiates a message request for requesting business data from the second office area, and sends the message request to the switch in the first office area;
[0014] The switch in the first office area sends the message request to the encryptor in the first office area.
[0015] Optionally, in the embodiment of the present application, the encryptor in the second office area performing decryption processing on the encrypted message to obtain the message request comprises the following steps:
[0016] The switch in the second office area receives the encrypted message sent by the global area and sends the encrypted message to the encryptor in the second office area;
[0017] The encryptor in the second office area performs decryption processing on the encrypted message to obtain the message request.
[0018] Optionally, in the embodiment of the present application, the method further comprises the following steps:
[0019] The non-virtual route forwarding area in the first office area initiates a non-encrypted message request, and the switch in the first office area sends the non-encrypted message request to the global area;
[0020] The global area performs route flow conversion processing on the non-encrypted message request and sends the non-encrypted message request to the switch in the target office area;
[0021] The switch in the target office area sends the non-encrypted message request to the non-virtual route forwarding area in the target office area.
[0022] The embodiment of the present application also provides a data encryption system based on virtual route forwarding technology, which comprises a global area and a plurality of office areas; wherein each office area is provided with a virtual route forwarding area, and the virtual route forwarding area is provided with an encryption machine and a service module; the office area comprises a first office area and a second office area;
[0023] The service module in the first office area initiates a message request for service data request to the second office area, the encryption machine in the first office area performs encryption processing on the message request to obtain an encrypted message, and the encryption machine in the first office area sends the encrypted message to the global area; wherein the service module and the encryption machine in the first office area are arranged in the virtual route forwarding area in the first office area;
[0024] The global area performs route flow processing on the encrypted message and sends the encrypted message to the second office area;
[0025] The encryption machine in the second office area performs decryption processing on the encrypted message to obtain the message request, and the service module in the second office area performs service processing by using the message request; wherein the encryption machine and the service module in the second office area are arranged in the virtual route forwarding area in the second office area.
[0026] Optionally, in the embodiment of the present application, the first office area is provided with an interactive machine; wherein the service module in the first office area initiates a message request for service data request to the second office area and sends the message request to the switch in the first office area; the switch in the first office area sends the message request to the encryption machine in the first office area.
[0027] Optionally, in the embodiment of the present application, the second office area is provided with an interactive machine; wherein the switch in the second office area receives the encrypted message sent by the global area and sends the encrypted message to the encryption machine in the second office area.
[0028] Optionally, in the embodiment of the present application, each office area is also provided with a non-virtual route forwarding area; wherein the non-virtual route forwarding area in the first office area initiates a non-encrypted message request, the switch in the first office area sends the non-encrypted message request to the global area, the global area performs route flow processing on the non-encrypted message request and sends the non-encrypted message request to the switch in the target office area, and the switch in the target office area sends the non-encrypted message request to the non-virtual route forwarding area in the target office area.
[0029] The application further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the method when executing the program.
[0030] The application further provides a computer readable storage medium, which stores a computer program for executing the method.
[0031] The application further provides a computer program product, comprising computer programs / instructions, which implement the steps of the method when executed by a processor.
[0032] The application increases the flexibility of deployment of encryption devices, reduces the deployment cost of encryption machines, and avoids the risk of interruption of other services due to the failure of encryption machines in the scenario of transparent mode deployment of encryption machines, and reduces the impact of the deployment of encryption machines on the existing network. BRIEF DESCRIPTION OF DRAWINGS
[0033] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiment description. Obviously, the drawings in the following description are only some embodiments of the application, and for those skilled in the art, other drawings can also be obtained from these drawings without creative labor.
[0034] Figure 1 The flow chart of the data encryption method based on the virtual routing forwarding technology in the embodiment of the application;
[0035] Figure 2 The flow chart of the message request initiation in the embodiment of the application;
[0036] Figure 3 The flow chart of the message request obtaining in the embodiment of the application;
[0037] Figure 4 The data flow conversion flow chart of the non-virtual routing forwarding area in the embodiment of the application;
[0038] Figure 5 The system structure schematic diagram of the application of the data encryption method based on the virtual routing forwarding technology in the embodiment of the application;
[0039] Figure 6 The system data flow conversion schematic diagram in the embodiment of the application;
[0040] Figure 7 The system message encryption processing schematic diagram in the embodiment of the application;
[0041] Figure 8A structural schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0042] The embodiment of the present application provides a data encryption method and system based on a virtual routing forwarding technology.
[0043] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative effort fall within the protection scope of the present application.
[0044] As Figure 1 FIG. 1 is a flowchart of a data encryption method based on a virtual routing forwarding technology according to an embodiment of the present application. The execution subject of the data encryption method based on the virtual routing forwarding technology provided by the embodiment of the present application includes but is not limited to a computer. The present application increases the flexibility of deployment of encryption devices, reduces the deployment cost of encryption machines, and does not affect high-speed and high-availability networks in the scenario of transparent mode deployment of encryption machines, meets the business requirements, avoids the risk of interruption of other businesses due to encryption machine failure, and reduces the impact of deployment of encryption machines on existing networks. Figure 1 The method includes the following steps.
[0045] In step S1, a business system in a first office area initiates a message request for requesting business data from a second office area, an encryption machine in the first office area performs encryption processing on the message request to obtain an encrypted message, and the encryption machine in the first office area sends the encrypted message to a global area. The business system in the first office area and the encryption machine are arranged in a virtual routing forwarding area in the first office area.
[0046] In step S2, the global area performs routing flow processing on the encrypted message and sends the encrypted message to the second office area.
[0047] In step S3, an encryption machine in the second office area performs decryption processing on the encrypted message to obtain the message request, and a business system in the second office area performs business processing by using the message request. The encryption machine in the second office area and the business system are arranged in a virtual routing forwarding area in the second office area.
[0048] The network device uses a virtual routing forwarding technology (VRF) to construct a VRF area (a virtual routing forwarding area), and the VRF area is deployed with a network layer encryption machine and a key business system (a business requiring encryption). According to business requirements, the VRF area can be deployed with multiple encryption machines. The encryption machine uses a transparent mode and is dedicated to a business data stream requiring encryption and decryption.
[0049] Further, the encrypted data stream is transferred between multiple office areas. Specifically, the business system of the first office area initiates a message request to the second office area, and the message request is used to request business data. The message request is first encrypted by the encryptor of the first office area to obtain an encrypted message. Specifically, the message encryption method is a conventional encryption method, which will not be described herein.
[0050] Further, the first office area and the second office area are provided with a virtual routing forwarding area and a non-virtual routing forwarding area. Specifically, the business system and the encryptor of the first office area are arranged in the virtual routing forwarding area. The business system arranged in the virtual routing forwarding area is a business system that needs to encrypt data, and other business systems that do not need to encrypt data are arranged in the non-virtual routing forwarding area.
[0051] Further, the switch arranged in the non-virtual routing forwarding area of the first office area sends the encrypted message to the global area. The global area routes and transfers the encrypted message to the switch of the second office area. Specifically, the first and the second are only used to distinguish the office areas and do not have specific meanings.
[0052] Further, the switch of the second office area sends the encrypted message to the encryptor of the second office area, and the encryptor of the second office area decrypts the encrypted message to obtain the message request. Specifically, the decryption method of the encrypted message is a conventional decryption method, which will not be described herein.
[0053] Further, the message request obtained after decryption is fed back to the switch by the encryptor of the second office area, and the switch sends the message request to the business system of the second office area. The business system of the second office area processes the business by using the message request. The specific business processing process is a conventional business processing, which will not be described herein.
[0054] Specifically, similar to the first office area, the second office area or other office areas are provided with a virtual routing forwarding area and a non-virtual routing forwarding area. Specifically, the encryptor and the business system that needs to encrypt data are arranged in the virtual routing forwarding area, and the switch and the business system that does not need to encrypt data are arranged in the non-virtual routing forwarding area. In addition, the business system in this embodiment is a business system that needs to encrypt data by default.
[0055] As an embodiment of the present application, as shown in Figure 2 The message request initiated by the business system in the first office area to request business data from the second office area includes:
[0056] Step S21, the business system in the first office area initiates a message request for a business data request to the second office area, and sends the message request to the switch in the first office area;
[0057] Step S22, the switch in the first office area sends the message request to the encryptor in the first office area.
[0058] Wherein, the switch in the first office area is arranged in a non-virtual route forwarding area, and after the business system initiates the message request, the message request is sent to the switch. The switch sends the message request to the encryptor in the first office area, and the encryptor encrypts the message request.
[0059] As an embodiment of the present application, as shown in Figure 3 The encryptor in the second office area decrypts the encrypted message to obtain the message request, including:
[0060] Step S31, the switch in the second office area receives the encrypted message sent by the global area, and sends the encrypted message to the encryptor in the second office area;
[0061] Step S32, the encryptor in the second office area decrypts the encrypted message to obtain the message request.
[0062] Wherein, similar to the first office area, the switch in the second office area is arranged in a non-virtual route forwarding area. The switch in the second office area receives the encrypted message sent by the global area, and then sends the encrypted message to the encryptor in the second office area, which decrypts the encrypted message.
[0063] As an embodiment of the present application, as shown in Figure 4 The method further comprises:
[0064] Step S41, the non-virtual route forwarding area in the first office area initiates a non-encrypted message request, and the switch in the first office area sends the non-encrypted message request to the global area;
[0065] Step S42, the global area routes and processes the non-encrypted message request, and sends the non-encrypted message request to the switch in the target office area;
[0066] Step S43, the switch in the target office area sends the non-encrypted message request to the non-virtual route forwarding area in the target office area.
[0067] In the non-encrypted data flow conversion, the service system in the non-virtual routing forwarding area in the first office area initiates a non-encrypted message request. The interworking machine in the first office area sends the non-encrypted message request to the global area. The global area routes and converts the non-encrypted message request and sends the non-encrypted message request to the switch in the target office area.
[0068] Further, the target office area can be a second office area or other office area. The interworking machine in the target office area receives the non-encrypted message request and sends the non-encrypted message request to the service system in the non-virtual routing forwarding area in the target office area, thereby completing the non-encrypted service processing.
[0069] The application increases the flexibility of the deployment of the encryption device, reduces the deployment cost of the encryption machine, and does not affect the high-speed and high-availability network in the transparent mode deployment scenario of the encryption machine, meets the service demand, avoids the risk of service interruption caused by the encryption machine failure, and reduces the influence of the deployment of the encryption machine on the existing network.
[0070] As Figure 5 The system structure schematic diagram of the application of the data encryption method based on the virtual routing forwarding technology in the embodiment of the application is shown in the figure, and the system shown in the figure includes a global area and a plurality of office areas. Each office area is provided with a virtual routing forwarding area, and the virtual routing forwarding area is provided with an encryption machine and a service module. The office area includes a first office area and a second office area.
[0071] The service module in the first office area initiates a message request for service data request to the second office area, the encryption machine in the first office area performs encryption processing on the message request to obtain an encrypted message, and the encryption machine in the first office area sends the encrypted message to the global area. The service module and the encryption machine in the first office area are arranged in the virtual routing forwarding area in the first office area.
[0072] The global area performs routing and conversion processing on the encrypted message and sends the encrypted message to the second office area.
[0073] The encryption machine in the second office area performs decryption processing on the encrypted message to obtain the message request, and the service module in the second office area performs service processing by using the message request. The encryption machine and the service module in the second office area are arranged in the virtual routing forwarding area in the second office area.
[0074] As an embodiment of the application, the first office area is provided with an interworking machine. The service module in the first office area initiates a message request for service data request to the second office area and sends the message request to the switch in the first office area. The switch in the first office area sends the message request to the encryption machine in the first office area.
[0075] As an embodiment of the present application, an interactive machine is arranged in the second office area; wherein the switch in the second office area receives the encrypted message sent by the global area, and sends the encrypted message to the encryptor in the second office area.
[0076] As an embodiment of the present application, a non-virtual route forwarding area is further arranged in each office area; wherein the non-virtual route forwarding area in the first office area initiates a non-encrypted message request, the switch in the first office area sends the non-encrypted message request to the global area; the global area performs route flow processing on the non-encrypted message request, and sends the non-encrypted message request to the switch in the target office area; the switch in the target office area sends the non-encrypted message request to the non-virtual route forwarding area in the target office area.
[0077] Specifically, taking the video conference service as an example, as shown in Figure 5 , in the global network area, the switches of each office area having encryption service requirements are configured with a VRF area, the encryptor and the service system requiring encryption and decryption are deployed in this area, and the encryptor is deployed in series and transparently to ensure that the encrypted data flows through the encryptor to reach the service system requiring encryption. Taking the video conference system as an encryption service, office area A, office area B and office area N build a VRF area, the video conference system is deployed in the VRF area of the office area, and the encryption device is deployed in a transparent mode and is connected in series between the global network area and the VRF area, so that all video conference data streams passing through the VRF area can pass through the encryption device.
[0078] Among them, as shown in Figure 6 , taking the data stream between office area A and office area B as an example, the encrypted data stream passes through the VRF area and the global area for route flow processing, realizing interconnection and intercommunication between different office areas. The data stream of other service systems only flows in the global area and does not pass through the VRF area. After passing through the encryptor, the data stream of the service system realizes encryption and decryption transmission, meeting the bidirectional encryption and decryption transmission requirements of the key service.
[0079] Further, the messages transmitted in the global area are divided into encrypted messages and non-encrypted messages, as shown in Figure 7 , taking the message flow of office area A accessing office area B as an example:
[0080] Regarding encrypted messages: 1) the VRF area video conference system of office area A initiates a data message request to office area B; 2) the encryption device of the VRF area of office area A collects the plaintext service data and performs message encryption; 3) the encrypted message is transferred to the global area, and the global area selects a route to transfer the encrypted message to the VRF area of office area B; 4) the encryption device of the VRF area of office area B collects the encrypted service data and performs message decryption; and 5) the VRF area video conference system of office area B receives the plaintext request.
[0081] Regarding non-encrypted messages: 1) the other service system of office area A initiates a data message request to the other service system of office area B, which is directly transferred to the global area; 2) the global area selects a route to transfer the message to office area B; and 3) the other service system of office area B receives the message request.
[0082] The present application is suitable for network layer encryption machine deployment and is suitable for encryption and decryption of service data streams that do not support address conversion, such as video conference data streams.
[0083] The present application increases the flexibility of encryption device deployment, reduces the deployment cost of encryption machines, and does not affect high-speed and high-availability networks in the scenario of transparent mode deployment of encryption machines, meets the service requirements, avoids the risk of interruption of other services due to encryption machine failure, and reduces the impact of the deployment of encryption machines on the existing network.
[0084] The present application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the above method when executing the program.
[0085] The present application also provides a computer program product, including computer programs / instructions, which are executed by the processor to implement the steps of the above method.
[0086] The present application also provides a computer readable storage medium, which stores a computer program for executing the above method.
[0087] As shown in Figure 8 , the electronic device 600 can also include a communication module 110, an input unit 120, an audio processor 130, a display 160, and a power supply 170. It should be noted that the electronic device 600 does not necessarily include all the components shown in Figure 8 ; in addition, the electronic device 600 can also include components not shown in Figure 8 , which can refer to prior art.
[0088] As shown in Figure 8As shown, the central processing unit 100, which is sometimes also referred to as a controller or operating control, can include a microprocessor or other processor device and / or logic device, which receives input and controls the operation of the various components of the electronic device 600.
[0089] The memory 140, for example, can be one or more of a buffer, a flash memory, a hard drive, a removable media, a volatile memory, a non-volatile memory, or other suitable device. Information relating to failures can be stored, and in addition, programs for executing the information can be stored. The central processing unit 100 can execute the programs stored in the memory 140 to achieve information storage or processing, etc.
[0090] The input unit 120 provides input to the central processing unit 100. The input unit 120 is, for example, a key or touch input device. The power supply 170 is used to provide power to the electronic device 600. The display 160 is used to display display objects such as images and text. The display can be, for example, an LCD display, but is not limited thereto.
[0091] The memory 140 can be a solid state memory, such as a read only memory (ROM), a random access memory (RAM), a SIM card, etc. It can also be a memory that retains information even when power is off, can be selectively erased, and is provided with more data, examples of which are sometimes referred to as EPROM, etc. The memory 140 can also be some other type of device. The memory 140 includes a buffer memory 141 (sometimes referred to as a buffer). The memory 140 can include an application / function storage section 142 for storing application programs and function programs or for storing a flow for executing the operation of the electronic device 600 by the central processing unit 100.
[0092] The memory 140 can also include a data storage section 143 for storing data such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. A driver program storage section 144 of the memory 140 can include various driver programs of the electronic device for a communication function and / or for executing other functions of the electronic device (such as a messaging application, an address book application, etc.).
[0093] The communication module 110 is a transmitter / receiver 110 that transmits and receives signals via an antenna 111. The communication module (transmitter / receiver) 110 is coupled to the central processing unit 100 to provide input signals and receive output signals, which can be the same as in the case of a conventional mobile communication terminal.
[0094] Based on different communication technologies, multiple communication modules 110, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, can be provided in the same electronic device. The communication module (transmitter / receiver) 110 is also coupled to a speaker 131 and a microphone 132 via an audio processor 130 to provide audio output via the speaker 131 and to receive audio input from the microphone 132 to enable typical telecommunication functions. The audio processor 130 can include any suitable buffers, decoders, amplifiers, etc. In addition, the audio processor 130 is coupled to the central processor 100 to enable recording of audio on the local device via the microphone 132 and to enable playing of stored audio on the local device via the speaker 131.
[0095] Those skilled in the art will appreciate that embodiments of the present application can be readily used as a method, a system, or a computer program product. A present application can be implemented in hardware- only embodiments, software-only embodiments, or embodiments combining software and hardware aspects. Furthermore, present application can take the form of a computer program product on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) embodying computer program instructions.
[0096] The present application is described in reference to the flowchart illustrations and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general purpose computer, special purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 means for performing one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks.
[0097] These computer program instructions can also be stored in a computer- readable memory that can direct a computer or other programmable data processing apparatus to function in a particular manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instructions which implement the flowchart illustrations and / or block diagrams block or blocks. Figure 1 one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks. Figure 1 means for performing one or more functions specified in the flowchart illustrations and / or block diagrams block or blocks.
[0098] These computer program instructions can also be loaded into a computer or other programmable data processing devices, so that a series of operational steps are generated to realize the computer-implemented processes, and the instructions executed on the computer or other programmable devices provide a process for implementing the functions specified in the flowchart Figure 1 one flow or multiple flows and / or the functions specified in the block Figure 1 one block or multiple blocks.
[0099] The principles and implementation manners of the present application are described in the specific embodiments. The above description of the embodiments is only used to help understand the method and core idea of the present application; meanwhile, for those skilled in the art, according to the idea of the present application, the specific implementation manners and application ranges can be changed, and the above description of the present application should not be understood as a limitation.
Claims
1. A data encryption method based on virtual route forwarding technology, characterized in that, The method comprises: The business system in the first office area initiates a message request for a business data request to the second office area, the encryption machine in the first office area performs encryption processing on the message request to obtain an encrypted message, and the encryption machine in the first office area sends the encrypted message to the global area; wherein the business system and the encryption machine in the first office area are arranged in a virtual route forwarding area in the first office area; The global area performs route flow conversion processing on the encrypted message and sends the encrypted message to the second office area; The encryption machine in the second office area performs decryption processing on the encrypted message to obtain the message request, and the business system in the second office area performs business processing using the message request; wherein the encryption machine and the business system in the second office area are arranged in a virtual route forwarding area in the second office area; The encryption machine is deployed in a serial transparent mode and is dedicated to the business data stream to be encrypted, the business system arranged in the virtual route forwarding area is a business system that needs to perform data encryption, and other business systems that do not need to perform data encryption are arranged in a non-virtual route forwarding area; The method further comprises: The non-virtual route forwarding area in the first office area initiates a non-encrypted message request, and the switch in the first office area sends the non-encrypted message request to the global area; The global area performs route flow conversion processing on the non-encrypted message request and sends the non-encrypted message request to the switch in the target office area; The switch in the target office area sends the non-encrypted message request to the non-virtual route forwarding area in the target office area.
2. The method of claim 1, wherein, The business system in the first office area initiates a message request for a business data request to the second office area comprises: The business system in the first office area initiates a message request for a business data request to the second office area and sends the message request to the switch in the first office area; The switch in the first office area sends the message request to the encryption machine in the first office area.
3. The method of claim 1, wherein, The encryption machine in the second office area performs decryption processing on the encrypted message to obtain the message request comprises: The switch in the second office area receives the encrypted message sent by the global area and sends the encrypted message to the encryption machine in the second office area; The encryption machine in the second office area performs decryption processing on the encrypted message to obtain the message request.
4. A data encryption system based on virtual route forwarding technology, characterized by, The system comprises a global area and a plurality of office areas; wherein each office area is provided with a virtual route forwarding area, and the virtual route forwarding area is provided with an encryption machine and a business module; the office areas comprise a first office area and a second office area; The service module in the first office area initiates a message request for a service data request to a second office area, an encryptor in the first office area encrypts the message request to obtain an encrypted message, and the encryptor in the first office area sends the encrypted message to a global area; wherein the service module and the encryptor in the first office area are arranged in a virtual route forwarding area in the first office area; The global area performs route flow conversion processing on the encrypted message and sends the encrypted message to the second office area; The encryptor in the second office area decrypts the encrypted message to obtain the message request, and a service module in the second office area performs service processing using the message request; wherein the encryptor and the service module in the second office area are arranged in a virtual route forwarding area in the second office area; The encryptor is deployed in a serial transparent mode and is dedicated to the service data stream to be encrypted, and a service system arranged in the virtual route forwarding area is a service system requiring data encryption, and other service systems not requiring data encryption are arranged in a non-virtual route forwarding area; Each office area further comprises a non-virtual route forwarding area; wherein the non-virtual route forwarding area in the first office area initiates a non-encrypted message request, the switch in the first office area sends the non-encrypted message request to the global area, the global area performs route flow conversion processing on the non-encrypted message request and sends the non-encrypted message request to a switch in a target office area, and the switch in the target office area sends the non-encrypted message request to the non-virtual route forwarding area in the target office area.
5. The system of claim 4, wherein, The first office area is provided with an interactive machine; wherein the service module in the first office area initiates a message request for a service data request to a second office area and sends the message request to the switch in the first office area, and the switch in the first office area sends the message request to the encryptor in the first office area.
6. The system of claim 4, wherein, The second office area is provided with an interactive machine; wherein the switch in the second office area receives the encrypted message sent by the global area and sends the encrypted message to the encryptor in the second office area.
7. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, The processor executes the computer program to implement the method of any one of claims 1 to 3.
8. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program for executing the method of any one of claims 1 to 3.
9. A computer program product comprising computer programs / instructions, characterized in that, The computer program / instruction is executed by the processor to implement the steps of the method of any one of claims 1 to 3.
Citation Information
Patent Citations
Method and device for establishing Internet safety protocol safety alliance
CN105812322A
Data encryption system and method
CN106453398A