Encrypted router, control method, device and equipment of encrypted router and medium
By utilizing the access restriction function of the encrypted router, the problem of data security risks for projects with different confidentiality levels on the same network was solved, enabling efficient and secure server testing.
Patent Information
- Application Number
- CN202310210216.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-07
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2043-03-07
AI Technical Summary
During the project development phase, the low security of existing switches leads to data security risks for development projects with different security levels on the same network, while building a separate test network for each project is too costly.
Design an encrypted router that restricts access between different ports by setting connection ports for the control unit and the server, ensuring network connectivity between the test control unit and the test server, prohibiting network connectivity between different servers, and employing encrypted transmission scripts to ensure data security.
Without setting up a dedicated testing environment, multiple project servers can be efficiently tested through the same network, ensuring that project data from different projects is not leaked, thus improving the security and flexibility of testing.
Smart Images

Figure CN116346670B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of server testing technology, and specifically relates to an encrypted router, a control method, device, equipment and medium for the encrypted router. Background Technology
[0002] During the project development phase, it is usually necessary to test the performance of the server, which requires the use of network devices such as switches to build a test network. However, switches have low security, so expensive routers are needed instead.
[0003] Typically, due to the high cost of setting up a test network, related technologies use the same network to test multiple different projects. However, having development projects with different security levels on the same network obviously poses a significant data security risk, while setting up a separate test network for each development project is too costly. Summary of the Invention
[0004] This application provides an encrypted router, a control method, apparatus, device, and medium for the encrypted router.
[0005] Some embodiments of this application provide an encrypted router, including: multiple server connection ports, a controller connection port, and a processor.
[0006] The control unit connection port is used to connect to the test control unit; the server connection port is used to connect to the test server; the other test equipment is used to connect to other test equipment.
[0007] The processor is configured to allow network connections to be established between ports in the router when the control unit connection port is connected to the test control unit; and to prohibit the establishment of network connections between ports in the router when the control unit connection port is not connected to the test control unit.
[0008] The processor is also configured to allow a network connection to be established between the server connection port and the controller connection port;
[0009] The processor is also used to prevent the establishment of network connections between multiple server connection ports.
[0010] Optionally, it also includes: other test equipment connection ports for connecting other test equipment besides the test server and the test controller;
[0011] The processor is also configured to allow the other test device connection port to establish a network connection with the controller connection port, and to prohibit the other test device connection port from establishing a network connection with the server connection port.
[0012] Optionally, the processor is further configured to, when detecting an access request input from the control unit connection terminal, verify the login password carried in the access request; and allow the test control unit to access the encrypted router when the login password verification is successful.
[0013] Optionally, the processor is further configured to receive a test script uploaded from the control unit connection port, and send the test script to the test server through the server connection port.
[0014] Optionally, the processor is further configured to send the encrypted test script to the test server through the server connection port.
[0015] Some embodiments of this application provide a control device for an encrypted router, the device comprising:
[0016] The transmission module is used to determine the target connection port to which the transmission data needs to be sent when it receives transmission data from the server connection port;
[0017] The processing module is used to intercept the transmitted data when the target connection port is also a server connection port;
[0018] When the target connection port is a control unit connection port and the control unit connection port is connected to the test control unit, the transmission data is sent to the test control unit through the control unit connection port.
[0019] When the target connection port is a controller connection port and the controller connection port is not connected to the test controller, the transmitted data is intercepted.
[0020] Optionally, the processing module is further configured to:
[0021] When receiving transmission data from the connection port of other test equipment, determine the target connection port to which the transmission data needs to be sent;
[0022] When the target connection port is a server connection port, the transmitted data is intercepted;
[0023] When the target connection port is the controller connection port, the transmission data is sent to the test controller through the controller connection port.
[0024] Some embodiments of this application provide a computing processing device, including:
[0025] Memory containing computer-readable code;
[0026] One or more processors, when the computer-readable code is executed by the one or more processors, the computing processing device performs the control method of the encrypted router as described above.
[0027] Some embodiments of this application provide a computer program including computer-readable code that, when executed on a computing processing device, causes the computing processing device to perform the control method for the encrypted router as described above.
[0028] Some embodiments of this application provide a non-transient computer-readable medium storing a control method for an encrypted router as described above.
[0029] The encrypted router, encrypted router control method, apparatus, device, and medium provided in some embodiments of this application, by setting up control machine connection ports and server connection ports with access restriction functions, enable the test control machine to efficiently test servers of multiple projects through the same network, even without setting up a dedicated test environment, so that when testing servers during the project development phase, the project data of different projects can be guaranteed not to be leaked, by restricting network connections between different server connection ports.
[0030] The above description is only an overview of the technical solution of this application. In order to better understand the technical means of this application and to implement it in accordance with the contents of the specification, and to make the above and other objects, features and advantages of this application more obvious and understandable, the following are specific embodiments of this application. Attached Figure Description
[0031] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0032] Figure 1 The schematic diagram illustrates the structure of an encrypted router provided in some embodiments of this application;
[0033] Figure 2 The diagram illustrates a test scenario of an encrypted router provided in some embodiments of this application.
[0034] Figure 3 The schematic diagram illustrates a flowchart of a control method for an encrypted router provided in some embodiments of this application;
[0035] Figure 4The schematic diagram illustrates a flowchart of another control method for an encrypted router provided in some embodiments of this application;
[0036] Figure 5 The schematic diagram illustrates the structure of a control device for an encrypted router according to some embodiments of this application;
[0037] Figure 6 A block diagram schematically illustrates a computing processing apparatus for performing methods according to some embodiments of this application;
[0038] Figure 7 A storage unit for holding or carrying program code implementing methods according to some embodiments of this application is illustrated schematically. Detailed Implementation
[0039] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0040] Figure 1 The schematic diagram illustrates the structure of an encrypted router 10 provided in this application, including: multiple server connection ports 102, a control unit connection port 101, and a processor 103.
[0041] The control unit connection port 101 is used to connect to the test control unit; the server connection port 102 is used to connect to the test server; the other test equipment is used to connect to other test equipment.
[0042] The processor 103 is used to allow network connections to be established between ports in the router when the controller connection port 101 is connected to the test controller; and to prohibit the establishment of network connections between ports in the router when the controller connection port 101 is not connected to the test controller.
[0043] The processor 103 is also configured to allow a network connection to be established between the server connection port 102 and the controller connection port 101;
[0044] The processor 103 is also used to prevent the establishment of network connections between multiple server connection ports 102.
[0045] In this embodiment of the application, the encrypted router is an intermediate device that carries data transmission between devices during server testing. The encryption function mainly includes authentication of access devices and authorization verification for transmission between devices.
[0046] Specifically, the encrypted router is equipped with at least a controller connection port 101 dedicated to connecting to the test controller, and a server connection port 102 dedicated to connecting to the test server. There can be one or more server connection ports 102. Since the server does not require high network speed for functional testing, multiple 1G Ethernet ports can be used as server connection ports 102 to reduce the configuration cost of the encrypted router. The controller connection port can also use a 1G Ethernet port or a higher specification Ethernet port. The specific configuration can be set according to the implementation requirements and is not limited here.
[0047] Considering that different test projects are conducted on the same network, there is a security risk of data leakage due to data transmission between test servers of different projects. Therefore, this embodiment of the application utilizes the processor 103 of the encrypted router to set access restrictions and identity restrictions for different connection ports. Specifically, for the control machine connection port 101, when connecting to the test control machine, the test control machine needs to provide a password to the encrypted router to verify whether the test control machine has access permissions. The control machine connection port 101 has the permission to access all connection ports on the encrypted router. It can be understood that since the test control machine can control the test servers of different projects, granting it access to all test servers can improve the efficiency of server testing.
[0048] For server connection port 102, the test server connected to it can only make network connections with the test control machine. In other words, different test servers cannot access each other through the server connection port 102 they are connected to. This ensures that there is no data interaction process between test servers of multiple projects under the same network, and avoids the risk of leakage of project data between test servers of different projects.
[0049] This application embodiment, by setting up a control machine connection port 101 and a server connection port 102 with access restriction function, ensures that when testing the server during the project development phase, even without setting up a dedicated test environment, by restricting network connections between different server connection ports 102, the test control machine can efficiently test the servers of multiple projects through the same network, while ensuring that project data of different projects is not leaked.
[0050] Optionally, refer to Figure 1 The encrypted router further includes: a connection port 104 for other test devices, used to connect to other test devices other than the test server and the test control machine;
[0051] The processor 103 is also configured to allow the other test device connection port 104 to establish a network connection with the controller connection port 101, and to prohibit the other test device connection port 104 from establishing a network connection with the server connection port 102.
[0052] In this embodiment of the application, in order to facilitate the participation of other test devices besides the test controller and test server in the server testing process, a dedicated connection port 104 for other test devices is also set on the encrypted router for them to join the test network.
[0053] Specifically, the other test device's connection port 104 also has access permissions. Other test devices need to log in and verify their identity through the encrypted router. After the encrypted router verifies their identity, they can access the encrypted router. However, the connection ports that can access the encrypted router are restricted. The other test device's connection port 104 can only transmit data with the control unit's connection port 101. The encrypted router prohibits it from transmitting data with the server's connection port 102, and also prohibits multiple other test devices from establishing connections between their connection ports 104. This provides an external connection interface for the server testing process while preventing project data from being obtained by external devices during the server testing process, thus improving the flexibility and security of the server testing process.
[0054] It is worth noting that, although Figure 1 There is only one other test device connection port 104 in the system, but in actual applications, the encrypted router 10 can be configured with multiple other test device connection ports 104 according to actual needs, so that the encrypted router 10 can connect to multiple other test devices at the same time, further improving the flexibility of the encrypted router 10 in the server testing process.
[0055] Optionally, the processor 103 is further configured to verify the login password carried in the access request when an access request is detected from the connection terminal of the control unit; and allow the test control unit to access the encrypted router when the login password verification is successful.
[0056] In this embodiment of the application, when the control unit connects to the encrypted router, it needs to provide a login password to prove its identity. The encrypted router only allows the test control unit to access the encrypted router after the login password is verified, so as to ensure the security of the test network.
[0057] Furthermore, for the aforementioned test servers and other external test devices, if they need to access the encrypted router's test network, they also need to provide the encrypted router with a login password to verify the device's identity, ensuring the legitimacy of the devices accessing the test network and guaranteeing the security of the server test.
[0058] Optionally, the processor 103 is further configured to receive a test script uploaded from the control unit connection port 101, and send the test script to the test server through the server connection port 102.
[0059] In this embodiment, during server testing, a test script can be uploaded to the encrypted router via the test control unit connected to port 101. This test script is a running program used to control the test server to perform server testing. The encrypted router can then automatically transmit the test script to the test server that needs to be tested, thereby enabling the test control unit to test a batch of test servers simultaneously, ensuring the consistency of testing progress between different test servers, and improving the accuracy of server test results.
[0060] Optionally, the processor 103 is further configured to send the encrypted test script to the test server through the server connection port 102.
[0061] In this embodiment, before distributing the test script to the test server, the encrypted router can encrypt the test script before transmitting it over the test network. The test server decrypts the test script upon receiving it before running the test, thus avoiding the risk of the test script being obtained by devices unrelated to the test. This further protects against the risk of project data leakage when multiple development projects are tested on the same network. For example, the SSH protocol can be used to transmit the test script. SSH is a network protocol used for encrypted login between computers. If a user logs into another remote computer from their local computer using the SSH protocol, we can consider this login secure; even if intercepted, the password will not be leaked.
[0062] For ease of understanding, please refer to Figure 2 Some embodiments of this application also provide usage scenarios for the encrypted router 10, wherein test server 31 and test server 32 belong to development project 1, and test server 33 and test server 34 belong to development project 2. Test server 31, test server 32, test server 33, and test server 34 can all be connected to the encrypted router 10 through server connection port 102. Test controller 21 can be added to the encrypted router 10 through controller connection port 101, and other test devices 22 can be connected to the encrypted router 10 through other test device connection port 104.
[0063] In the same network environment carried by the encrypted router 10, after the encrypted router 10 verifies the login password provided by the test control machine 21, it allows the test control machine 21 to access and obtains the test script 1 of development project 1 and the test script 2 of development project 2 from the test control machine 21. Then, the encrypted router 10 sends the test script 1 to the test server 31 and test server 32 involved in development project 1, and sends the test script 2 to the test server 33 and test server 34 involved in development project 1.
[0064] During server testing, because the encrypted router 10 prohibits communication between the server connection ports 102 connected to test servers 31, 32, 33, and 34, project data for development project 1 and development project 2 cannot be transmitted between the test servers, thus preventing leakage of development projects with different security levels between the test servers. As for the test control machine 10, it can communicate with each server connection port 102 through its connected control machine connection port 101. That is, the test control machine 21 can simultaneously control the server testing process of test servers 31, 32, 33, and 34, enabling efficient server testing.
[0065] Furthermore, the other test device connection port 104 provided by the encrypted router 10 allows other test devices 22 to access the network. The test controller 21 can obtain network connection permission with other test devices 22 by entering a password, so that other test devices 22 can participate in the server testing process of the development project through the other test device connection port 104.
[0066] Figure 3 The schematic diagram illustrates a flow chart of a control method for an encrypted router provided in this application, the method comprising:
[0067] Step 201: When receiving transmission data from the server connection port, determine the target connection port to which the transmission data needs to be sent.
[0068] Step 202: When the target connection port is also a server connection port, intercept the transmitted data.
[0069] Step 203: When the target connection port is a control unit connection port and the control unit connection port is connected to the test control unit, the transmission data is sent to the test control unit through the control unit connection port.
[0070] Step 204: When the target connection port is a controller connection port and the controller connection port is not connected to the test controller, the transmitted data is intercepted.
[0071] The execution entity in this application embodiment can be the processing of the encryption router in some of the above embodiments. For details, please refer to the above description, which will not be repeated here.
[0072] This application embodiment, by setting access restriction functions on the control machine connection port and server connection port, ensures that during the project development phase, when testing the server, even without setting up a dedicated test environment, network connections between different server connection ports are prevented. This allows the test control machine to efficiently test servers of multiple projects through the same network while ensuring that project data from different projects is not leaked.
[0073] Optionally, refer to Figure 4 The method further includes:
[0074] Step 301: When receiving transmission data from the connection port of other test equipment, determine the target connection port to which the transmission data needs to be sent.
[0075] Step 302: When the target connection port is a server connection port, intercept the transmitted data.
[0076] Step 303: When the target connection port is the control unit connection port, the transmission data is sent to the test control unit through the control unit connection port.
[0077] Optionally, the method further includes: disabling network connections between all connection ports in the encrypted router when the control unit connection port has not established a network connection with the test control unit.
[0078] Optionally, the method further includes: when an access request is detected from the connection terminal of the control unit, verifying the login password carried in the access request; and allowing the test control unit to access the encrypted router when the login password is verified.
[0079] The specific description of the control method of an encrypted router provided in some embodiments of this application is similar to the execution process of the processor in an encrypted router provided in some embodiments of this application. To avoid repetition, it will not be described again here.
[0080] Figure 5 The schematic diagram illustrates the structure of a control device 40 for an encrypted router provided in this application. The device includes:
[0081] The transmission module 401 is used to determine the target connection port to which the transmission data needs to be sent when it receives transmission data from the server connection port;
[0082] Processing module 402 is used to intercept the transmitted data when the target connection port is also a server connection port;
[0083] When the target connection port is a control unit connection port and the control unit connection port is connected to the test control unit, the transmission data is sent to the test control unit through the control unit connection port.
[0084] When the target connection port is a controller connection port and the controller connection port is not connected to the test controller, the transmitted data is intercepted.
[0085] Optionally, the processing module 402 is further configured to:
[0086] When receiving transmission data from the connection port of other test equipment, determine the target connection port to which the transmission data needs to be sent;
[0087] When the target connection port is a server connection port, the transmitted data is intercepted;
[0088] When the target connection port is the controller connection port, the transmission data is sent to the test controller through the controller connection port.
[0089] Optionally, the processing module 402 is further configured to:
[0090] If the control unit connection port does not establish a network connection with the test control unit, network connections between all connection ports in the encrypted router are disabled.
[0091] Optionally, the processing module 402 is further configured to:
[0092] When an access request is detected from the control unit connection terminal, the login password carried in the access request is verified;
[0093] When the login password verification is successful, the test control machine is allowed to access the encrypted router.
[0094] This application embodiment, by setting access restriction functions on the control machine connection port and server connection port, ensures that during the project development phase, when testing the server, even without setting up a dedicated test environment, by restricting network connections between different server connection ports, the test control machine can efficiently test servers of multiple projects through the same network, while also ensuring that project data of different projects is not leaked.
[0095] The various component embodiments of this application can be implemented in hardware, or as software modules running on one or more processors, or a combination thereof. Those skilled in the art will understand that microprocessors or digital signal processors (DSPs) can be used in practice to implement some or all of the functions of some or all of the components in the computing processing device according to the embodiments of this application. This application can also be implemented as a device or apparatus program (e.g., a computer program and computer program product) for performing part or all of the methods described herein. Such an implementation of this application can be stored on a non-transient computer-readable medium, or can be in the form of one or more signals. Such signals can be downloaded from an Internet website, provided on a carrier signal, or provided in any other form.
[0096] For example, Figure 6 A computing processing apparatus is shown that can implement the methods according to this application. This computing processing apparatus conventionally includes a processor 510 and a computer program product or non-transitory computer-readable medium in the form of a memory 520. The memory 520 may be an electronic memory such as flash memory, EEPROM (Electrically Erasable Programmable Read-Only Memory), EPROM, hard disk, or ROM. The memory 520 has a storage space 530 for program code 531 for performing any of the method steps described above. For example, the storage space 530 for program code may include various program codes 531 respectively for implementing the various steps in the methods described above. These program codes can be read from or written to one or more computer program products. These computer program products include program code carriers such as hard disks, CDs, memory cards, or floppy disks. Such computer program products are typically as shown in the reference. Figure 7 The portable or fixed storage unit is described above. This storage unit may have the same characteristics as... Figure 6 The memory 520 in the computing processing device is arranged similarly to storage segments, storage spaces, etc. Program code can be compressed, for example, in an appropriate form. Typically, the storage unit includes computer-readable code 531', that is, code that can be read by a processor such as 510, which, when run by the computing processing device, causes the computing processing device to perform the various steps in the methods described above.
[0097] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0098] The terms "an embodiment," "embodiment," or "one or more embodiments" as used herein mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment of this application. Furthermore, please note that the examples of the phrase "in one embodiment" do not necessarily all refer to the same embodiment.
[0099] Numerous specific details are set forth in the specification provided herein. However, it will be understood that embodiments of this application may be practiced without these specific details. In some instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this specification.
[0100] In the claims, any reference signs placed between parentheses should not be construed as limiting the claims. The word "comprising" does not exclude the presence of elements or steps not listed in the claims. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. This application can be implemented by means of hardware comprising several different elements and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by the same item of hardware. The use of the words first, second, and third, etc., does not indicate any order. These words can be interpreted as names.
[0101] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. An encryption router, characterized by The method comprises: a plurality of server connection ports, control machine connection ports, processors: the control machine connection port is used for connecting a test control machine; the server connection port is used for connecting a test server; the processor is used for allowing network connection to be established between ports in the router when the control machine connection port is connected with a test control machine; when the control machine connection port is not connected with a test control machine, the processor is used for prohibiting network connection to be established between ports in the router; the processor is also used for allowing network connection to be established between the server connection port and the control machine connection port; the processor is also used for prohibiting network connection to be established between a plurality of the server connection ports.
2. The cryptographic router of claim 1, wherein, Further comprising: other test equipment connection ports, which are used for connecting other test equipment other than the test server and the test control machine; the processor is also used for allowing network connection to be established between the other test equipment connection port and the control machine connection port, and prohibiting network connection to be established between the other test equipment connection port and the server connection port.
3. The cryptographic router of claim 1, wherein, When the processor detects an access request input from the control machine connection port, the processor is used for verifying a login password carried by the access request; and when the login password is verified, the processor is used for allowing the test control machine to access the encrypted router.
4. The cryptographic router of claim 1, wherein, The processor is also used for receiving a test script uploaded from the control machine connection port, and sending the test script to the test server through the server connection port.
5. The cryptographic router of claim 4, wherein, The processor is also used for sending the encrypted test script to the test server through the server connection port.
6. A control method of a cryptographic router, characterized by, The method comprises: when receiving transmission data from a server connection port, determining a target connection port to which the transmission data needs to be sent; the server connection port is used for connecting a test server; when the target connection port is also a server connection port, intercepting the transmission data; when the target connection port is a control machine connection port and the control machine connection port is connected with a test control machine, sending the transmission data to the test control machine through the control machine connection port; when the target connection port is a control machine connection port and the control machine connection port is not connected with a test control machine, intercepting the transmission data.
7. The method of claim 6, wherein, The method further comprises: when receiving transmission data from an other test equipment connection port, determining a target connection port to which the transmission data needs to be sent; when the target connection port is a server connection port, intercepting the transmission data; when the target connection port is a control machine connection port, sending the transmission data to a test control machine through the control machine connection port.
8. A control device of a cryptographic router, characterized by, The device comprises: a transmission module, which is used for, when receiving transmission data from a server connection port, determining a target connection port to which the transmission data needs to be sent; the server connection port is used for connecting a test server; a processing module, which is used for, when the target connection port is also a server connection port, intercepting the transmission data; a processing module, which is used for, when the target connection port is a control machine connection port, sending the transmission data to a test control machine through the control machine connection port. when the target connection port is a control machine connection port and the control machine connection port is connected with a test control machine, sending the transmission data to the test control machine through the control machine connection port; when the target connection port is a control machine connection port and the control machine connection port is not connected with a test control machine, intercepting the transmission data.
9. A computing processing device, comprising: comprising: a memory having stored thereon computer readable code; one or more processors, the computing device, when executing the computer readable code with the one or more processors, performs the control method of the cryptographic router as claimed in any one of claims 6-7.
10. A non-transitory computer-readable medium, comprising: a computer program having stored thereon the control method of the cryptographic router as claimed in any one of claims 6-7.
Citation Information
Patent Citations
Network interface card test system
CN105429816A
System for providing an isolated testing model for disaster recovery capabilites
US20180248937A1