Data Security Protection Method Based on Link Layer Transparent Encryption
By capturing and encrypting data packets at the link layer transparent encryption method, the existing data encryption methods are solved, real-time and reliable encryption protection of data is achieved, and the security of data transmission and network compatibility are ensured.
Patent Information
- Application Number
- CN202411070954.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-06
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2044-08-06
AI Technical Summary
Existing data encryption methods are costly and have poor compatibility at the application layer, transport layer and network layer, making them difficult to achieve seamless integration and affect network performance, and end-to-end encryption methods are difficult to monitor and manage network devices.
Using a transparent encryption method based on link layer, by configuring a transparent encryption model, data packets are captured and encryption processed at link layer, only data payloads are encrypted, IP header information is dynamically updated, and packet integrity and confidentiality are ensured.
Real-time encryption of data at the link layer is realized, real-time and reliability of encryption is improved, confidentiality and integrity of data transmission is ensured, while not affecting the existing network structure and applications, and maintaining network compatibility and scalability.
Smart Images

Figure CN119254454B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of network data technologies, and in particular, to a data security protection method based on link layer transparent encryption. Background Art
[0002] With the rapid development of information technology and the wide popularization of network applications, data security has become one of the major challenges faced by today's society. Traditional data encryption methods are usually implemented at the application layer or the transport layer, and these methods often require modifying the existing network structure or application programs, resulting in problems such as high implementation costs and poor compatibility.
[0003] Specifically, the encryption technologies disclosed in the prior art mainly include the following aspects: 1) Encryption at the application layer, that is, it is necessary to modify the application program, which is complex to implement and difficult to seamlessly integrate with the existing system; 2) Encryption at the transport layer, such as SSL / TLS, although widely used, may increase the processing overhead and affect the network performance; 3) Encryption at the network layer, such as IPSec, usually requires modifying the network configuration, increasing the deployment difficulty; 4) End-to-end encryption methods, although having high security, are difficult to implement the monitoring and management functions of network intermediate devices; 5) Encryption in the traditional link layer, this method usually requires dedicated hardware, with high costs and poor flexibility. Summary of the Invention
[0004] In view of this, the embodiments of the present disclosure provide a data security protection method based on link layer transparent encryption, which can solve the problem that the encryption scheme in the prior art affects the existing network structure and applications.
[0005] In a first aspect, the embodiments of the present disclosure provide a data security protection method based on link layer transparent encryption, and the method specifically includes the following solutions:
[0006] Based on a configuration file or user input information, determine a plurality of network interfaces of the configured transparent encryption model, and set the modes of the plurality of network interfaces to promiscuous mode;
[0007] Start the promiscuous mode, capture all the original data packets passing through the target link based on the transparent encryption model, and filter the original data packets to obtain a plurality of original data packets that need to be encrypted, denoted as a plurality of first data packets;
[0008] Parse the first data packet based on the transparent encryption model to obtain the information of the IP header;
[0009] Based on the information of the IP header, determine the start position and length of the IP packet data payload, and based on the start position and the length, determine the target data payload;
[0010] Encrypt the target data payload based on a preset encryption algorithm and an encryption key to obtain an encrypted data payload;
[0011] Based on the encrypted data payload, dynamically update the information in the IP header;
[0012] Recombine the updated information in the IP header with the encrypted data payload into an encrypted data packet, and forward the encrypted data packet to the target interface.
[0013] Optionally, the transparent encryption model includes a data packet capture policy, a data packet filtering policy, a data packet parsing policy, a data packet encryption policy, and a forwarding policy;
[0014] The data packet capture policy includes capture filter information, capture buffer size information, capture mode information, the size information of the data packet to be captured, and a preset function.
[0015] Optionally, the dynamically updating the information in the IP header based on the encrypted data payload includes:
[0016] Based on the encrypted data payload, change the total length of the IP header, and the sum of the changed total length of the IP header and the total length of the encrypted data payload is consistent with the total length of the original data packet;
[0017] Based on the changed total length of the IP header, update the checksum of the IP header to obtain an updated IP header.
[0018] Optionally, the recombining the updated information in the IP header with the encrypted data payload into an encrypted data packet includes:
[0019] Configure a recombination buffer, and the size of the recombination buffer is not less than the sum of the size of the updated IP header and the size of the encrypted data payload;
[0020] In the recombination buffer, recombine the updated IP header with the encrypted data payload to obtain an encrypted data packet.
[0021] Optionally, the recombining the updated IP header with the encrypted data payload in the recombination buffer to obtain an encrypted data packet includes:
[0022] Copy the updated IP header to the start position of the recombination buffer;
[0023] Place the encrypted data payload after the copied position of the updated IP header, and the setting position of the encrypted data payload is adjacent to the copied position of the updated IP header.
[0024] Optionally, it further includes: adding metadata during the encryption process, where the metadata includes one or more of an initialization vector and an authentication tag;
[0025] The size of the reorganization buffer is not less than the sum of the size of the updated IP header, the size of the encrypted data payload, and the size of the metadata;
[0026] In the reorganization buffer, the copying position of the metadata is between the copying position of the updated IP header and the setting position of the encrypted data payload.
[0027] Optionally, if the original data packet is a fragment, update the fragment offset based on the size of the encrypted data packet;
[0028] If the encrypted data packet needs to be fragmented for transmission, divide the encrypted data packet into several blocks, and update the fragment offset and more fragments flag for each block.
[0029] Optionally, the preset encryption algorithm includes the AES algorithm or the ChaCha20 algorithm;
[0030] The method for obtaining the encryption key includes:
[0031] Determine the initial parameters of the preset key negotiation mechanism;
[0032] Obtain the local key pair of each communication party based on the initial parameters, where the local key pair includes a local private key and a local public key;
[0033] Exchange the local public keys of each communication party based on a preset security protocol;
[0034] Obtain a shared key based on the local private key and the other party's public key; the other party's public key is the local public key sent by the exchanging party received by the communication party corresponding to the local public key;
[0035] Generate an encryption key from the shared key using a key derivation function.
[0036] Optionally, the exchanging of the local public keys of each communication party based on a preset security protocol includes:
[0037] Determine the certificate information of the digital certificate, where the certificate information includes certificate standards, certificate formats, certificate chain information, certificate verification mechanisms, and certificate storage mechanisms;
[0038] Formulate a two-way authentication protocol policy based on the certificate information;
[0039] Authenticate the identities of the first end and the second end based on the two-way authentication protocol policy and the certificate information. After passing the identity authentication, exchange the local public keys of each communication party based on a preset security protocol;
[0040] The first end is the first communication party, and the second end is the second communication party for which public key exchange is to be performed.
[0041] Optionally, the transparent encryption model further includes a storm control policy;
[0042] Before forwarding the encrypted data packet, analyze the traffic pattern in the network where the encrypted data packet is located to determine the traffic type that induces a storm;
[0043] Dynamically regulate based on the traffic type and the storm control policy;
[0044] The storm control policy includes one or more of a rate limiting policy, a token bucket algorithm policy, a leaky bucket algorithm, a broadcast storm control policy, a multicast storm control policy, and a priority queue policy.
[0045] In a second aspect, an embodiment of the present disclosure further provides a data security protection system based on link layer transparent encryption, including:
[0046] A setting module, configured to determine a plurality of network interfaces of the configured transparent encryption model based on a configuration file or user input information, and set the modes of the plurality of network interfaces to promiscuous mode;
[0047] A filtering module, configured to start the promiscuous mode, capture all raw data packets passing through the target link based on the transparent encryption model, and filter the raw data packets to obtain a plurality of raw data packets that need to be encrypted, denoted as a plurality of first data packets;
[0048] An obtaining module, configured to parse the first data packet based on the transparent encryption model to obtain information of the IP header;
[0049] A determining module, configured to determine the start position and length of the IP packet data payload based on the information of the IP header, and determine the target data payload based on the start position and the length;
[0050] An encryption module, configured to encrypt the target data payload based on a preset encryption algorithm and an encryption key to obtain an encrypted data payload;
[0051] An updating module, configured to dynamically update the information of the IP header based on the encrypted data payload;
[0052] A recombination module, configured to recombine the updated information of the IP header with the encrypted data payload into an encrypted data packet, and forward the encrypted data packet to the target interface.
[0053] In a third aspect, an embodiment of the present disclosure further provides a computer device, adopting the following technical solution:
[0054] The computer device includes:
[0055] at least one processor; and,
[0056] a memory communicatively connected to the at least one processor; wherein,
[0057] the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the data security protection method based on link layer transparent encryption described in any one of the above.
[0058] In a fourth aspect, an embodiment of the present disclosure further provides a computer-readable storage medium storing computer instructions for causing a computer to execute the data security protection method based on link layer transparent encryption described in any one of the above.
[0059] In a fifth aspect, an embodiment of the present disclosure further provides a computer program product including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the method described in any one of the above are implemented.
[0060] The data security protection method based on link layer transparent encryption disclosed in this application captures all data packets when data is transmitted through a link, filters out the data that needs to be protected in real time and performs encryption processing, realizing the encryption of data at the network link layer. That is, the method can start protecting directly when data enters the physical link, avoiding the exposure of data at other network levels, improving the real-time and reliability of encryption, and ensuring the confidentiality and integrity of data during transmission; at the same time, the encryption technology that only encrypts the data payload of IP packets enables the encryption device (i.e., the transparent encryption model) to be directly connected in series to the network without configuring an IP address or modifying the network structure, that is, it will not affect the existing network structure and applications, etc., and can effectively ensure the normal operation of the existing network system and various devices. The data security protection method based on link layer transparent encryption disclosed in this application not only improves the security of data transmission, but also ensures the compatibility and scalability of the network.
[0061] The above description is only an overview of the technical solution of the present disclosure. In order to understand the technical means of the present disclosure more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features and advantages of the present disclosure more obvious and understandable, the following preferred embodiments are specifically given and described in detail in conjunction with the drawings as follows. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] To more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following will briefly introduce the accompanying drawings required for the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0063] Figure 1 It is a flowchart showing the process of the data security protection method based on link layer transparent encryption provided by the embodiments of the present disclosure.
[0064] Figure 2 It is a flowchart showing the process of the dynamic update method of the information of the IP header provided by the embodiments of the present disclosure.
[0065] Figure 3 It is a flowchart showing the process of the reorganization method of encrypted data packets provided by the embodiments of the present disclosure.
[0066] Figure 4 For Figure 3 It is a flowchart showing the process of the reorganization method of the updated IP header and the encrypted data payload in the reorganization buffer in
[0067] Figure 5 It is a flowchart showing the process of the method for obtaining an encryption key provided by the embodiments of the present disclosure.
[0068] Figure 6 It is a flowchart showing the process of the method for local public key exchange between different communication parties provided by the embodiments of the present disclosure.
[0069] Figure 7 It is a principle block diagram of the data security protection system based on link layer transparent encryption provided by the embodiments of the present disclosure.
[0070] Figure 8 It is a structural diagram of a computer device provided by the embodiments of the present disclosure. Detailed implementation manners
[0071] The following will describe the embodiments of the present disclosure in detail with reference to the accompanying drawings.
[0072] It should be clear that the following uses specific specific examples to illustrate the implementation modes of the present disclosure. Those skilled in the art can easily understand other advantages and effects of the present disclosure from the content disclosed in this specification. Obviously, the described embodiments are only a part of the embodiments of the present disclosure, rather than all the embodiments. The present disclosure can also be implemented or applied through other different specific implementation modes. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present disclosure. It should be noted that, without conflict, the following embodiments and the features in the embodiments can be combined with each other. Based on the embodiments in the present disclosure, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by the present disclosure.
[0073] It should be noted that the following describes various aspects of the embodiments within the scope of the appended claims. It should be obvious that the aspects described herein can be embodied in a wide variety of forms, and any specific structure and / or function described herein is illustrative only. Based on the present disclosure, those skilled in the art should understand that one aspect described herein can be implemented independently of any other aspect, and two or more of these aspects can be combined in various ways. For example, any number of aspects described herein can be used to implement the device and / or practice the method. In addition, this device and / or this method can be implemented using other structures and / or functions in addition to one or more of the aspects described herein.
[0074] It also should be noted that the diagrams provided in the following embodiments only schematically illustrate the basic concept of the present disclosure. The diagrams only show the components related to the present disclosure and are not drawn according to the number, shape, and size of the components in actual implementation. The type, quantity, and ratio of each component in its actual implementation can be arbitrarily changed, and the component layout type may also be more complex.
[0075] In addition, in the following description, specific details are provided to facilitate a thorough understanding of the examples. However, those skilled in the art will understand that the described aspects can be practiced without these specific details.
[0076] Refer to Figure 1 , this application discloses a data security protection method based on link layer transparent encryption, including:
[0077] S100, configure a transparent encryption model.
[0078] Specifically, the transparent encryption model includes a data packet capture policy, a data packet filtering policy, a data packet parsing policy, a data packet encryption policy, and a forwarding policy. Among them, the data packet capture policy preferably includes capture filter information, capture buffer size information, capture mode information, the size information of the data packets to be captured, and a preset function.
[0079] By setting the capture buffer size information, it can adapt to high-traffic environments so as to capture as many data packets as possible in high-traffic environments. Because too small a buffer may cause data packet loss, while too large a buffer may occupy too much memory.
[0080] By setting the capture filter information, it can ensure that only the data packets of interest are captured, which helps to reduce unnecessary data packet captures and improve processing efficiency.
[0081] By setting the capture mode information, it can be selected whether to enable the promiscuous mode so as to capture all data packets passing through the network interface, rather than just the data packets sent to the local address.
[0082] By setting the size information of the data packets to be captured, the size of the captured data packets is determined, including whether to capture the entire data packet or only the header of the data packet. Capturing the entire data packet can provide more detailed information, but it will increase the storage and processing burden.
[0083] The preset function can be a callback function, which will be triggered whenever a new data packet arrives. The capture process needs to be efficient and reliable to ensure that no data packets are lost.
[0084] The setting of the forwarding policy can implement the data packet forwarding function to ensure normal network communication. Specifically, a continuously running loop can be designed to read data packets from the network interface, and each captured data packet needs to be processed and forwarded. This process is the core of the data packet forwarding function and requires consideration of efficiency and reliability.
[0085] The setting of the data packet parsing policy can be used to parse the content of the data packets after capture, which includes extracting key information such as the source MAC address, the destination MAC address, and the protocol type. The parsing process needs to understand the structures of various network protocols to correctly identify and process different types of data packets.
[0086] To forward data packets efficiently, the system needs to implement the MAC address learning function, which involves creating and maintaining a MAC address table to record the exit interface corresponding to each MAC address. Each time a data packet is received, this table is updated to reflect the changes in the network topology.
[0087] Based on the parsed information and the MAC address table, forwarding decisions can be made, which include determining which interface the data packet should be forwarded to, or whether a broadcast is required; if the destination MAC address is unknown, the system may need to perform a flooding operation.
[0088] Once the forwarding decision is made, the next step is to actually send the data packet, which involves using the appropriate network API to transmit the data packet to the target interface. The sending process needs to handle possible errors to ensure the successful transmission of the data packet.
[0089] Furthermore, the transparent encryption model can be a transparent encryption device configured between the core switch and the department switch in the enterprise intranet, or the transparent encryption model can be a transparent encryption function module integrated into the virtual network management platform, or the transparent encryption model can be a transparent encryption module integrated into the IoT gateway device.
[0090] S200, based on the configuration file or user input information, determine several network interfaces of the transparent encryption model, and set the modes of the several network interfaces to promiscuous mode.
[0091] Promiscuous mode allows the network card to capture all data packets transmitted through the physical link, not just the data of the target interface.
[0092] In this step, the system needs to identify the available network interfaces, which is usually achieved by using the network API provided by the operating system or a dedicated network library. The system will obtain a list of all available network interfaces, including their names, types, and current status; specifically, according to the configuration file or user input, select the specific interfaces that need to be set to promiscuous mode.
[0093] After selecting the interface, the next step is to set it to promiscuous mode, which usually involves using specific system calls or network library functions. In promiscuous mode, the network interface will capture all passing data packets, not just the data packets targeted at the local machine.
[0094] Furthermore, after the promiscuous mode is set up, it also includes: verifying whether the promiscuous mode is successfully enabled, which can be done by checking the interface status or specific system files. The verification process ensures that the interface is indeed in the expected working mode and prepares for subsequent data packet capture.
[0095] S300, start the promiscuous mode, capture all the original data packets passing through the target link based on the transparent encryption model, and filter the original data packets to obtain several original data packets that need to be encrypted, denoted as several first data packets.
[0096] Among them, the target link refers to the target network link.
[0097] Filter the captured original data packets, and only the data packets that need to be encrypted will be selected to form the first set of data packets (i.e., several first data packets), that is, only the data part that needs to be protected is encrypted, which can effectively improve the efficiency and response speed of the system.
[0098] S400, based on the transparent encryption model, parse the first data packet to obtain the information of the IP header.
[0099] For each selected original data packet, parse its first data packet through the transparent encryption model, and extract the information of the IP header therein. The IP header contains important information such as the starting position and length of the target data payload.
[0100] Specifically, the information of the IP header may include important information such as the source IP address, the destination IP address, and the protocol type information.
[0101] S500, based on the information of the IP header, determine the starting position and length of the IP packet data payload, and based on the starting position and length, determine the target data payload.
[0102] In this step, the first data packet includes the IP header and the IP packet data payload. The data payload is the actual data content being transmitted. According to the parsed IP header information, determine the starting position and length of the target data payload in the original data packet. This step is to accurately determine the target data payload.
[0103] After identifying the IP packet structure, the next step is to extract the data payload part from the entire IP packet. This process needs to be extremely careful to ensure that the header information is not accidentally included; therefore, it is necessary to accurately calculate the starting position and length of the data payload according to the information in the IP header, such as the total length field and the header length field.
[0104] S600, encrypt the target data payload based on the preset encryption algorithm and encryption key to obtain the encrypted data payload.
[0105] The preset encryption algorithm includes algorithms such as the AES algorithm or the ChaCha20 algorithm and other algorithms. The selection of the encryption algorithm needs to consider factors such as security, performance, and resource consumption.
[0106] Use the prepared encryption algorithm and key to encrypt the extracted data payload. This process needs to be carried out efficiently to minimize the impact on network performance; the encryption operation should be atomic to ensure the integrity of the data; if the data payload is large, block encryption may need to be considered to optimize performance.
[0107] The encrypted data payload ensures the confidentiality of the data, that is, only authorized recipients can decrypt and read its content.
[0108] In this step, only the target data payload is encrypted, and the original IP header information is retained. That is, during the encryption process, the original IP header information must be completely retained. This includes all fields such as the source IP address, destination IP address, protocol type, time to live (TTL), etc. Retaining this information is crucial for ensuring that the data packet can be correctly routed to the destination.
[0109] S700, based on the encrypted data payload, dynamically updates the information in the IP header.
[0110] Specifically, although most of the IP header information remains unchanged, some fields may need to be updated. In particular, if the encryption process changes the total length of the data packet, the total length field in the IP header needs to be updated accordingly.
[0111] S800, recombines the updated information in the IP header with the encrypted data payload into an encrypted data packet, and forwards the encrypted data packet to the target interface.
[0112] It should be noted that if, during the process of encrypting the target data payload, the size, length, or other information in the IP header does not change, the actual operation corresponding to the dynamic update instruction in S700 is to do nothing, and the information in the updated IP header included in the recombined encrypted data packet is still the information of the original IP header.
[0113] The data security protection method based on link layer transparent encryption disclosed in this application captures all data packets when the data is transmitted through the link, filters out the data that needs to be protected in real time and performs encryption processing, realizing the encryption of data at the network link layer. That is, this method can start protecting directly when the data enters the physical link, avoiding the exposure of data at other network levels, improving the real-time performance and reliability of encryption, and ensuring the confidentiality and integrity of data during the transmission process; at the same time, the encryption technology that only encrypts the IP packet data payload enables the encryption device (i.e., the transparent encryption model) to be directly connected in series to the network without configuring an IP address or modifying the network structure, that is, it will not affect the existing network structure and applications, etc., and can effectively ensure the normal operation of the existing network system and various devices. The data security protection method based on link layer transparent encryption disclosed in this application not only improves the security of data transmission, but also ensures the compatibility and scalability of the network.
[0114] Refer to Figure 2 , the method for dynamically updating the information in the IP header specifically includes the following steps:
[0115] S710, based on the encrypted data payload, changes the total length of the IP header, and the sum of the changed total length of the IP header and the total length of the encrypted data payload is the same as the total length of the original data packet.
[0116] When a data packet needs to be encrypted, the encryption process may cause the size of the data packet to change. For example, additional information required for encryption is added. To ensure that the size of the entire data packet is the same as that of the original data packet, it is necessary to adjust the total length field of the IP header.
[0117] Specifically, assume that the size of the original data packet is X bytes, and the size of the encrypted data packet is Y bytes, where the encryption process adds Z bytes of additional information. Then the new IP header length should be X + Z.
[0118] Through this step, the integrity of the data packet can be maintained, ensuring that the data packet will not be discarded or misprocessed due to size changes during transmission; when encrypting the data payload, the data content is hidden, increasing the security of information protection.
[0119] S720, based on the total length of the changed IP header, update the checksum of the IP header to obtain the updated IP header.
[0120] The IP header contains a header checksum field used to verify the integrity of the header during transmission. Since some fields (such as the total length) may have been modified, it is necessary to recalculate and update this checksum. This step is very important for ensuring that the data packet can be correctly processed by network devices.
[0121] When the total length of the IP header changes, the original checksum needs to be recalculated to adapt to the new header structure.
[0122] After the total length of the IP header changes, recalculate the checksum of the IP header. Specifically, if the IP header length and checksum of the original data packet are L1 and C1 respectively, and the IP header length of the encrypted data packet becomes L2, then the updated IP header checksum C2 should be the checksum calculated based on the new IP header length L2.
[0123] In this step, by updating the checksum, the integrity of the data packet during transmission is ensured, avoiding transmission errors caused by changes in the IP header, and ensuring that the receiving party can correctly verify the integrity of the data packet, improving the reliability and stability of communication.
[0124] In the method for dynamically updating the information of the IP header disclosed in the embodiment, encrypting the data payload ensures the privacy and security of the data, and dynamically updating the IP header guarantees the high efficiency and reliability of data packet transmission, can be compatible with existing network communication protocols, and does not affect the normal operation of network communication.
[0125] In this embodiment, if the original IP contains IP options, special care needs to be taken. These options are usually located after the standard IP header and before the data payload. The encryption process should not change or encrypt these options, but their positions may need to be adjusted to fit the encrypted data structure.
[0126] Some protocols (such as ICMP) may rely on the content of the IP data payload for operation. In this case, special processing mechanisms may need to be implemented to ensure that the encrypted packets are still compatible with these protocols.
[0127] After all necessary adjustments are completed, a comprehensive verification of the modified IP header can be performed to ensure that all necessary fields remain unchanged or are correctly updated to maintain the integrity and validity of the packet.
[0128] Through these detailed steps, the encryption of the IP packet data payload can be achieved while keeping the IP header information unchanged. This method ensures data security without affecting the normal routing and processing functions of the network layer. In actual implementation, factors such as performance optimization and exception handling also need to be considered to ensure that the system can operate stably and efficiently under various network conditions.
[0129] Refer to Figure 3 , the method for reassembling the encrypted packet specifically includes the following steps:
[0130] S810, configure a reassembly buffer, and the size of the reassembly buffer is not less than the sum of the size of the updated IP header and the size of the encrypted data payload.
[0131] Through this step, it can be ensured that the memory space of the configured reassembly buffer is large enough to accommodate the reassembled IP packet.
[0132] Furthermore, if additional metadata (such as an initialization vector or an authentication tag) is added during the encryption process, the space for these additional data also needs to be considered.
[0133] Specifically, the minimum size of the reassembly buffer can be calculated based on the size of the updated IP header and the encrypted data payload to ensure that it can accommodate the sum of these two parts. Memory management functions provided by programming languages or operating systems can be used to allocate a large enough memory block as the reassembly buffer, and at the same time ensure that the size of the reassembly buffer is not less than the sum of the updated IP header and the encrypted data payload to avoid overflow or data loss problems.
[0134] In this step, by preallocating and optimizing the memory space, the efficiency and stability of the program can be improved. Ensuring that the reassembly buffer is large enough can effectively prevent data truncation or accidental modification.
[0135] S820, Reassemble the updated IP header and the encrypted data payload in the reassembly buffer to obtain an encrypted data packet.
[0136] Specifically, copy the content of the updated IP header to the starting position of the reassembly buffer; immediately following the IP header, copy the content of the encrypted data payload into the reassembly buffer, closely connecting it behind the IP header. At this time, the data inside the reassembly buffer is the complete encrypted data packet, which contains the updated IP header and the encrypted data payload.
[0137] In this step, it can ensure that the IP header and the encrypted data payload are correctly combined together to form a complete encrypted data packet, which can reduce the additional overhead caused by scattered data during network transmission and improve the data transmission efficiency.
[0138] The method for reassembling the encrypted data packet disclosed in this embodiment, through step-by-step processing, ensures the consistency and correctness of the data inside the reassembled encrypted data packet; by reasonably configuring the size of the reassembly buffer and memory management, it improves the resource utilization efficiency of the system, and can avoid system crashes or security issues caused by improper data processing, enhancing the stability and security of the system.
[0139] Refer to Figure 4 which is Figure 3 the flow schematic diagram of the method for reassembling the updated IP header and the encrypted data payload in the reassembly buffer in
[0140] S821, Copy the updated IP header to the start position of the reassembly buffer.
[0141] Specifically, obtain the data content of the updated IP header, which usually includes information such as source address, destination address, protocol type, packet length, etc.; copy the obtained IP header data byte by byte or bit by bit to the starting position of the reassembly buffer; confirm the exact position of the copied IP header in the reassembly buffer so that the insertion point of the encrypted data payload can be correctly located in subsequent steps.
[0142] In this step, it can ensure that the beginning part of the encrypted data packet is the correct IP header information, guaranteeing the identification and processing capabilities of the data packet during network transmission; through simple copy operations, the rapid embedding of the IP header is achieved, reducing complex data processing steps.
[0143] S822, Place the encrypted data payload after the copy position of the updated IP header, and the setting position of the encrypted data payload is adjacent to the copy position of the updated IP header.
[0144] Specifically, according to the position of the updated IP header in the reassembly buffer, the exact position where the encrypted data payload should be inserted is calculated, usually after the end of the IP header copy; then the content of the encrypted data payload is copied byte by byte or bit by bit to the calculated insertion position, while confirming that all the content of the encrypted data payload has been correctly inserted into the reassembly buffer.
[0145] In this step, the integrity and correctness of the encrypted data payload can be ensured, avoiding the risk of data loss or tampering; by directly inserting the data without additional complex calculations, the efficiency and speed of data processing are improved.
[0146] The solution disclosed in this embodiment can effectively manage and reassemble network data packets, and is particularly applicable to network communication scenarios that require encryption and transmission of data packets, ensuring the secure transmission and efficient processing of data.
[0147] The data security protection method based on link-layer transparent encryption disclosed in this application further includes: adding metadata during the encryption process, and the metadata includes one or more of an initialization vector and an authentication tag;
[0148] The size of the reassembly buffer is not less than the sum of the size of the updated IP header, the size of the encrypted data payload, and the size of the metadata;
[0149] In the reassembly buffer, the copy position of the metadata is between the copy position of the updated IP header and the setting position of the encrypted data payload.
[0150] The benefits of this method are mainly reflected in data security protection. Specifically, by adding metadata (such as an initialization vector and an authentication tag) during the encryption process, the security and reliability of data encryption can be improved. In addition, the design of the reassembly buffer takes into account the size of the updated IP header, the size of the encrypted data payload, and the size of the metadata, ensuring the integrity and availability of the encrypted data. The copy position of the metadata is set at a suitable position between the updated IP header and the encrypted data payload, which helps to effectively manage the processing and reassembly process of the encrypted data, further strengthening the security during the data transmission process. In summary, this method not only focuses on the encryption protection of data, but also pays attention to the metadata management and reassembly design during the protection process to ensure the security and integrity of data during transmission and storage.
[0151] In this application, if the original data packet is a fragment, the fragment offset is updated based on the size of the encrypted data packet;
[0152] If the encrypted data packet needs to be fragmented for transmission, the encrypted data packet is divided into several blocks, and the fragmentation of each block is updated.
[0153] Fragment offset and more fragments flag.
[0154] In this embodiment, the determination of whether an encrypted data packet needs to be fragmented for transmission specifically includes: determining whether the size of the encrypted data packet exceeds the maximum fragmentation size allowed by the transmission protocol. If so, it is determined that the encrypted data packet needs to be fragmented for transmission.
[0155] In this embodiment, the encryption process should not affect these fields to ensure the correct recombination of the fragments.
[0156] In the case of processing the fragmented transmission of an encrypted data packet, two main steps are involved: updating the fragment offset and the fragment flag. When the original data packet is a fragment, the fragment offset refers to the offset of the fragment relative to the starting position of the original data packet. When recombining the encrypted data packet, the fragment offset of each fragment needs to be updated according to the size of the encrypted data packet to ensure that they correctly correspond to their positions in the encrypted data packet.
[0157] Specifically, assuming that the size of the encrypted data packet exceeds the maximum capacity of a single fragment, then the fragment offset of each fragment needs to be adjusted accordingly to reflect its correct position in the encrypted data packet. This is usually achieved by recalculating the fragment offset to ensure that all fragments can be correctly restored to the complete encrypted data packet after recombination.
[0158] If the encrypted data packet needs to be further fragmented for transmission, even the encrypted data packet needs to be divided into smaller chunks (fragments) during transmission. The information that needs to be updated for each chunk includes the fragment offset and the more fragments flag.
[0159] Specifically, each fragment needs to update its fragment offset to ensure that it can be correctly recombined into the original encrypted data packet at the receiving end. At the same time, the more fragments (MF) flag needs to be set to indicate whether there are more fragments waiting to be transmitted.
[0160] Among them, the more fragments flag specifically includes: the MF flag of the first fragment is set to 1, indicating that there are more fragments behind; the MF flag of the middle fragments is also set to 1, indicating that there are more fragments behind; the MF flag of the last fragment is set to 0, indicating that this is the last fragment.
[0161] For example, assume that the size of the original data packet is 5000 bytes and the maximum fragmentation size allowed by the protocol is 1000 bytes. Therefore, the original data needs to be divided into 5 fragments for transmission. After encryption, the size of the data packet becomes 5500 bytes, so it needs to be divided into 6 fragments.
[0162] The original fragments include: Fragment 1: 1000 bytes, MF = 1; Fragment 2: 1000 bytes, MF = 1; Fragment 3: 1000 bytes, MF = 1; Fragment 4: 1000 bytes, MF = 1; Fragment 5: 1000 bytes, MF = 0.
[0163] In this example, the encrypted data packet requires an additional fragment, so it is necessary to update the MF flags of all fragments and ensure that the MF flag of the last fragment is 0.
[0164] By transmitting in fragments, it is possible to avoid problems such as transmission delays or packet losses caused by overly large individual data packets, improving the transmission efficiency of data; updating the fragment offset and fragment flags can ensure that the receiving end can correctly reconstruct the encrypted data packet, guaranteeing the integrity and reliability of the data; and at the same time, it can adapt to different network environments and transmission conditions, ensuring that the data packet can be effectively transmitted and reconstructed in the network.
[0165] By updating the fragment offset and fragment flags, it is possible to effectively manage and transmit the fragments of the encrypted data packet, ensuring the secure transmission and efficient processing of the data, and at the same time ensuring the stability and reliability of the system in various network environments.
[0166] Attach the encrypted data payload to the buffer, immediately following the IP header (and possibly encrypted metadata). This process needs to ensure the alignment and integrity of the data, especially when dealing with large data packets. If the encryption process generates metadata (such as an initialization vector) that needs to be transmitted together with the data, this data usually needs to be inserted at a position after the IP header and before the encrypted data payload. By carefully designing the format and position of this metadata, it is ensured that the receiving party can correctly identify and use them.
[0167] Refer to Figure 5 , and the method for obtaining the encryption key specifically includes the following steps:
[0168] A100, determine the initial parameters of the preset key negotiation mechanism.
[0169] Specifically, determine the Diffie - Hellman (DH) variant to be used, such as classic DH, Elliptic Curve DH (ECDH), etc.; select appropriate security parameters. For the Diffie - Hellman (DH) variant, these parameters include prime number p, generator g, or select a suitable elliptic curve (for ECDH), ensuring that the selected parameters comply with the latest security standards and recommendations.
[0170] In this step, determining the initial parameters can ensure that all communication parties use consistent basic settings, simplifying the implementation of key negotiation; selecting standardized key negotiation mechanisms and parameters can improve the compatibility and interoperability of the system.
[0171] A200 obtains a local key pair for each communication party based on initial parameters. The local key pair includes a local private key and a local public key.
[0172] Specifically, a private key is generated for each communication party, which is usually a large randomly selected integer; the public key is calculated based on the private key and the initial parameters, ensuring that each communication party generates its own key pair, that is, each communication party has its own key pair, ensuring the privacy and security of key generation; at the same time, key pair generation is independent, and each communication party only needs to generate its own key without relying on the key information of other parties.
[0173] Among them, a cryptographically secure random number generator (CSPRNG) can be used to generate the private key.
[0174] A300 exchanges the local public keys of each communication party based on a preset security protocol.
[0175] A secure protocol can be designed to exchange public keys, which can involve using a pre-established secure channel or leveraging digital signatures to implement a serialization and deserialization mechanism for public keys, ensuring integrity during network transmission; at the same time, timestamps or sequence numbers can also be considered to prevent replay attacks.
[0176] Specifically, the local public key Q of each communication party is exchanged using a preset security protocol (such as TLS). Communication party A sends its local public key Q A to communication party B, and communication party B also sends its local public key Q B to communication party A; the public keys are exchanged through an encrypted channel (such as using TLS) to protect the data security during the exchange process.
[0177] Through this step, it can be ensured that all communication parties can obtain the public keys of other parties for calculating the shared key; exchanging public keys through an encrypted channel reduces man-in-the-middle attacks and other potential security threats.
[0178] Furthermore, the received public key can also be verified, that is, a public key verification mechanism is implemented to check whether the received public key is valid and has not been tampered with.
[0179] For ECDH, ensure that the received public key is indeed on the specified elliptic curve; additional security measures for public key verification can also be considered, such as using certificates or pre-shared keys.
[0180] A400 obtains a shared key based on the local private key and the public key of the other party; the public key of the other party is the local public key received by the communication party corresponding to the local public key from the exchanging party.
[0181] Specifically, the DH shared key is calculated using the local private key and the received public key of the other party.
[0182] Among them, for classical DH, this involves modular exponentiation; for ECDH, this involves point multiplication. To ensure that the implemented algorithm can handle large integers, a specialized large number library can be used.
[0183] Each communicating party calculates the shared key using its own local private key and the public key of the other party. For example, communicating party A uses its private key d A and the public key Q of communicating party B B , and calculates the shared key K = d A times Q B . Communicating party B then uses its private key d B and the public key Q of communicating party A A , and calculates the shared key K = d B times Q A .
[0184] In this step, the calculation process of the shared key utilizes the mathematical properties of the key pair, ensuring the security and uniqueness of the generated shared key, and at the same time ensuring that both parties can generate the same shared key for subsequent encryption and decryption operations.
[0185] A500, uses a key derivation function to generate an encryption key from the shared key.
[0186] Specifically, a key derivation function (such as HKDF, PBKDF2, etc.) can be used to generate the actual session key from the DH shared key.
[0187] Using the shared key as input, the final encryption key is generated through a key derivation function. The key derivation function can further process the shared key, adding a salt value, the number of iterations, etc., to enhance the security of the key.
[0188] Consider generating multiple keys for different purposes (such as encryption keys, authentication keys); further, other context information (such as the identities of both parties, protocol version) can also be included in the key derivation process to enhance security.
[0189] The key derivation function can enhance the security of the key, resist various attacks, such as brute force cracking, and can generate multiple keys for different purposes (such as encryption, signature, etc.) to meet different security requirements.
[0190] The method for obtaining the encryption key disclosed in this embodiment ensures the security and reliability of the encryption key through a standardized key negotiation and generation mechanism; uses standard protocols and methods (such as Diffie-Hellman, ECDH, TLS, etc.) to ensure the compatibility and interoperability of the system; provides strong data protection through the use of encryption key generation and key derivation functions, ensuring the confidentiality and integrity of information; the entire process uses modern encryption technologies to reduce potential security risks such as man-in-the-middle attacks and key leakage.
[0191] Furthermore, this application also includes: verifying the key negotiation result. Specifically, implement a key confirmation step to ensure that both parties have successfully generated the same session key, which can be completed by exchanging and verifying a predefined message encrypted with the newly generated key; consider using key-based authentication methods such as HMAC to verify the correctness of the key.
[0192] This application also includes regularly updating the session key through a key update strategy to improve security. Specifically, the key update strategy includes: determining the conditions for triggering key update, such as time interval, data volume threshold, or session duration; considering the network environment and application scenarios, balancing security and performance requirements, a flexible strategy can be designed to allow adjustment of the update frequency according to actual needs.
[0193] This application also includes implementing a key update protocol. Specifically, design a secure protocol to coordinate the key update process between both parties, including version numbers or timestamps, to prevent downgrade attacks and replay attacks, and consider using the current session key to protect the key update process itself.
[0194] This application also includes generating new key materials. Specifically, use a cryptographically secure random number generator to create a new DH private key, and then calculate the corresponding new public key; different DH parameters (such as different prime numbers or elliptic curves) can also be considered to increase diversity.
[0195] This application also includes securely exchanging the new public key. Specifically, encrypt the new public key with the current session key for transmission, and a mechanism can be implemented to confirm that both parties have successfully received the new public key; additional authentication mechanisms such as digital signatures can also be considered to verify the authenticity of the new public key.
[0196] This application also includes calculating a new shared key. Specifically, calculate the new DH shared key using the new private key and the received new public key; verify that the newly generated shared key is different from the previous key; an error handling mechanism can also be included to handle the situation of key calculation failure.
[0197] This application also includes deriving a new session key. Specifically, a new session key is generated from the new shared key using a key derivation function. Additionally, extra context information such as the update count or timestamp can be considered during the key derivation process to ensure the secure isolation of old and new key materials and prevent potential key leakage.
[0198] This application also includes synchronously switching to the new key. Specifically, a mechanism can be designed to coordinate both parties to simultaneously switch to the new session key. A short transition period can also be considered during which both old and new keys are accepted simultaneously to handle network latency. Further, a rollback mechanism can be considered to address potential issues during the key update process.
[0199] This application also includes securely destroying the old key. Specifically, this is to implement secure memory erasure technology to thoroughly clear the old key material. Consider using specialized secure memory management techniques such as memory rewriting or using encrypted memory regions to ensure that sensitive key information is not leaked in logs and error reports.
[0200] This application also includes verifying and recording key updates. Implement a process to verify the correctness and validity of the new key. Record key update events, including timestamps and relevant metadata, but do not record the actual key material. Consider implementing an audit mechanism to track and analyze key update patterns.
[0201] Through these detailed steps, a secure key negotiation mechanism based on the Diffie - Hellman algorithm can be implemented, and the session key is updated regularly to improve security. This method ensures that both communicating parties can establish and maintain a secure encryption channel, while reducing the risk of potential key leakage through regular updates. In actual implementation, factors such as performance optimization, error recovery, compatibility, and scalability also need to be considered to ensure that the system can operate securely and efficiently in various network environments and usage scenarios.
[0202] Refer to Figure 6 , the method for local public key exchange between different communication parties provided by the embodiments of the present disclosure specifically includes the following steps:
[0203] B100, determine the certificate information of the digital certificate. The certificate information includes the certificate standard, certificate format, certificate chain information, certificate verification mechanism, and certificate storage mechanism.
[0204] Among them, the certificate standard can be X.509, which is a widely used standard for defining the format and content of digital certificates.
[0205] The certificate format can be the PEM (Privacy Enhanced Mail) encoding format or the DER (Distinguished Encoding Rules) encoding format, and these formats specify the encoding method of certificate data.
[0206] The certificate chain information includes: defining the hierarchical relationship of the certificate chain, including the root certificate, intermediate certificate, and end-entity certificate; the root certificate is issued by a trusted certificate authority (CA), the intermediate certificate is used to verify the root certificate, and the end-entity certificate is used for the specific communicating parties.
[0207] The certificate verification mechanism includes how to verify the validity, integrity, and authenticity of the signature of the certificate, such as through the Certificate Revocation List (CRL) or the Online Certificate Status Protocol (OCSP).
[0208] The certificate storage mechanism is used to determine the location and method of certificate storage, such as storing on the local disk, in a Hardware Security Module (HSM), or through a public certificate repository.
[0209] In this step, following the standardized certificate format and verification mechanism can ensure the consistency and interoperability of the system; by defining a detailed certificate chain and verification mechanism, the security and credibility of the certificate are enhanced; the systematic certificate storage and management strategy simplifies the process of using and maintaining the certificate.
[0210] Furthermore, it can also include: a certificate error handling mechanism, that is, developing a detailed error reporting mechanism that can accurately describe the reason for the failure of certificate verification, implementing a flexible error handling strategy, and allowing bypassing specific verification steps in certain situations (such as emergencies). User-friendly error prompts can be designed to help administrators or users understand and solve certificate problems.
[0211] B200, formulating a mutual authentication protocol strategy based on the certificate information.
[0212] Among them, the mutual authentication protocol strategy includes the first-end identity authentication strategy, the second-end identity authentication strategy, and the authentication order strategy, that is, the authentication of the identity of each end can be achieved through the mutual authentication protocol strategy.
[0213] Specifically, standard protocols such as TLS with client authentication or custom protocols can be used; the protocol message format therein can include certificate exchange, challenge-response mechanism, etc.
[0214] B300, performing the identity authentication of the first end and the second end based on the mutual authentication protocol strategy and the certificate information. After passing the identity authentication, exchange the local public keys of each communicating party based on the preset security protocol;
[0215] The first end is the first communication party, and the second end is the second communication party for which public key exchange is to be performed.
[0216] In this embodiment, the second communication party and the first communication party form a key exchange group.
[0217] Specifically, for the identity authentication of the first end (such as a server), the first communication party (the first end) sends its digital certificate to the second communication party (the second end), and the second end verifies the validity and authenticity of the certificate to verify the identity of the first end.
[0218] For the identity authentication of the second end (such as a client), the second communication party (the second end) also sends its digital certificate to the first communication party, and the first end verifies the validity and authenticity of the certificate to verify the identity of the second end.
[0219] Furthermore, the identity authentication includes the verification of digital certificates and / or key authentication.
[0220] The method for verifying digital certificates specifically includes: verifying the validity of digital certificates. Among them, the certificate chain verification process includes checking whether the certificate is issued by a trusted CA, as well as the validity of intermediate certificates and root certificates, which involves: verifying the signature, that is, ensuring that the signature of the server certificate is signed by a trusted CA and can be verified through the root certificate chain; checking the validity period, requiring that the validity period of the certificate is within the current date; checking certificate revocation, that is, verifying whether the certificate has been revoked through the Certificate Revocation List (CRL) or the Online Certificate Status Protocol (OCSP); hostname verification, that is, the client also needs to verify whether the hostname in the certificate matches the actual server hostname accessed.
[0221] This process includes: extracting the hostname, that is, extracting the hostname from the "Subject" field or "SubjectAlternative Name" field in the certificate; matching the extracted hostname with the server hostname requested by the client to ensure they are the same.
[0222] The method for key authentication specifically includes: taking the identity authentication of the first end as an example, the first end can sign some data by using its private key to prove that it actually holds the corresponding private key. The first end signs a piece of data with its private key and attaches the signature to the certificate or sends it to the second end in the handshake protocol. The second end can use the public key of the server (extracted from the certificate) to verify the validity of the signature. The second end verifies the signature with the public key to ensure that the first end actually holds the private key that matches the public key in the certificate.
[0223] The proof of key possession verifies that the first party indeed possesses the private key corresponding to its certificate, enhancing the credibility of the first party's identity authentication; through the proof of key possession, the second party can confirm that the server's certificate is not only legal, but also the first party indeed possesses the matching key, further ensuring the security of communication.
[0224] After both parties successfully pass the identity authentication, it is confirmed that both communicating parties are verified legal entities.
[0225] Through digital certificates and the two-way authentication mechanism, the authenticity and legality of the identities of both communicating parties are ensured; successful identity authentication establishes a trust foundation between the two communicating parties, laying the foundation for subsequent public key exchange and encrypted communication. At the same time, it can prevent malicious attackers from forging identities or interfering with the communication process, effectively improving the security of the system.
[0226] Exchange the local public keys of each communicating party based on a preset security protocol, including: select a preset security protocol, such as TLS (Transport Layer Security Protocol), to encrypt the public key exchange process; after successful two-way authentication, both parties exchange their local public keys through the security protocol. The first party sends its public key to the second party, and the second party also sends its public key to the first party; use the security protocol to encrypt the public key exchange process to ensure that the public key is not stolen or tampered with during transmission.
[0227] In this step, encrypting the public key exchange process through the security protocol protects the public key from man-in-the-middle attacks or data tampering; the public key exchange after two-way authentication ensures that the received public key indeed comes from a legitimate communicating party; integrating the public key exchange process into the existing security protocol simplifies the implementation process and improves efficiency.
[0228] The method for local public key exchange between different communicating parties disclosed in this embodiment ensures the authenticity of the identities of both communicating parties through digital certificates and the two-way authentication mechanism, encrypts the public key exchange process through the security protocol, enhances the overall security of the system, adopts standardized certificates and authentication mechanisms, improves the compatibility and interoperability of the system, and successful two-way authentication establishes a trust foundation between the two communicating parties, providing guarantee for secure data transmission and key exchange. At the same time, it can reduce security risks such as man-in-the-middle attacks and forged identities, and improve the protection ability of the system.
[0229] Furthermore, this application also includes: integrating the two-way authentication process with the Diffie-Hellman key exchange while ensuring that the integrity of the authentication process is not affected by the key exchange process.
[0230] Furthermore, this application also includes: binding the negotiated session key to the authenticated identity to ensure that the generated key corresponds to the actual authenticated identity, which helps prevent the key from being used in other unauthenticated communication sessions. Through identity binding, it can be verified that the key is indeed used for an authenticated session, improving the credibility of communication.
[0231] Furthermore, this application also includes: implementing a session recovery mechanism that allows the reuse of an authenticated session within a short period, thereby avoiding the overhead of re-authentication and key negotiation each time, for the purpose of improving performance and efficiency. Specifically, the authenticated session information (such as session key, authentication status) can be cached so that it can be quickly retrieved and used during session recovery. When recovering the session, a specific protocol or identifier is used to confirm and restore the previous session state instead of re-performing authentication and key exchange, which can effectively reduce the frequency of re-authentication and key exchange, improve the system's response speed and performance, and at the same time can effectively reduce the computational and network overheads generated by re-performing authentication and key negotiation.
[0232] Furthermore, this application also includes: considering implementing a key derivation function for deriving additional key materials, that is, the key derivation function allows other key materials to be derived from the already negotiated session key, and these keys can be used for different purposes, such as encryption, message authentication code (MAC), or other security operations. Specifically, use a key derivation function to generate additional key materials from the session key, and these functions ensure that the generated key materials have the required security and randomness; define the types and uses of the derived keys, and ensure that the key derivation process complies with security requirements and does not disclose or abuse the session key.
[0233] Furthermore, this application also includes: integrating the authentication result with an access control system to achieve fine-grained permission control based on certificate attributes (such as extended fields), and developing a dynamic permission adjustment mechanism that allows real-time adjustment of user permissions based on the authentication result.
[0234] Specifically, combine the results in the authentication process (such as user identity, role, permission) with the access control system so that the authenticated user can access system resources according to their identity and permission.
[0235] Furthermore, develop an interface or module so that the authentication system and the access control system can exchange information in real time. For example, when a user is successfully authenticated, the system can configure corresponding permissions in the access control system based on the user's identity information.
[0236] Through integration, it is possible to uniformly manage user identities and permissions in one system, improve management efficiency, and ensure that only authenticated users can access specific resources, enhancing the security of the system.
[0237] Implementing fine-grained permission control based on certificate attributes means using the attributes in digital certificates (such as extension fields, certificate issuer information, etc.) to achieve refined access control. Specifically, the attribute information in the certificate can be extracted, such as the user's role, department, permissions, etc.; then detailed permission rules can be defined in the access control system based on these attributes. For example, the "department" field included in the user's certificate can be used to restrict access to resources of certain departments, providing more detailed and precise permission management, enabling users to only access the resources they are authorized to, and different permission rules can be defined according to different attributes in the certificate, improving the flexibility of permission management.
[0238] The developed dynamic permission adjustment mechanism allows the system to adjust the user's permissions according to real-time situations or authentication results after user authentication. This mechanism is usually used to cope with dynamically changing requirements or security requirements. Specifically, the implementation mechanism can monitor the user's status and permission requests in real time to decide whether to adjust the permissions, and automatically adjust the user's permissions based on the authentication results and the policies in the system. For example, if the user's authentication information indicates that they have completed additional training, their permissions can be automatically elevated.
[0239] Furthermore, a policy engine can be designed to dynamically adjust the user's permissions according to the authentication results and current environmental conditions, which can quickly adapt to changes in user identity or business requirements, improving the flexibility of the system. By dynamically adjusting the permissions, potential security threats can be responded to in a timely manner, reducing risks.
[0240] Furthermore, this application also includes the management of authentication sessions, specifically including the creation, maintenance, and destruction mechanisms of authentication sessions, developing session timeout and re-authentication policies, and implementing a secure session logout mechanism.
[0241] The creation of an authentication session includes creating a session after the user successfully completes authentication, which usually contains the user's identity information, permissions, session identifier, etc. The session can be stored on the server side (such as in memory, database) or on the client side (such as in the browser's session storage).
[0242] Among them, the session identifier is a unique session ID generated as an identifier to recognize the user's session.
[0243] The maintenance of an authentication session refers to maintaining the session status during the validity period of the session to ensure that the user's operations and access permissions are correctly processed.
[0244] The destruction mechanism of an authentication session means that the session needs to be destroyed when it is no longer needed (such as when the user logs out, the session expires, etc.) to release resources and protect the user's privacy. Specifically, the session data is deleted from the storage, and the validity of the session ID is terminated to prevent the session from being maliciously used.
[0245] Furthermore, this application also includes recording all authentication-related activities, including authentication attempts and results, which can help monitor the authentication process, diagnose problems, track security incidents, etc. Among them, authentication attempts include recording the time of each authentication attempt, user identity (or identifier), authentication method (such as password, fingerprint), authentication result (success or failure), etc.
[0246] Furthermore, this application also includes configuring a secure log storage and transmission mechanism, which aims to prevent log data from being tampered with, lost, or leaked, ensuring the integrity and confidentiality of log data. Specifically, encryption technology can be used to encrypt log data to prevent unauthorized access or tampering. Specifically, log data can be stored in a protected storage medium, such as a controlled server or a dedicated log storage service.
[0247] Furthermore, this application also includes configuring an audit function that allows administrators to trace back and analyze the authentication history for security auditing and compliance checks.
[0248] Furthermore, this application also includes configuring an error handling and failure recovery mechanism, which means that when a user authentication fails, a friendly and useful error message is provided, and at the same time, the failure situation is handled to ensure that the user experience is not overly affected.
[0249] Specifically, friendly and useful means providing a clear, concise error message without technical details, such as "The username or password is incorrect", avoiding disclosing too much information (such as whether the specific username exists) to reduce potential security risks.
[0250] Furthermore, a retry policy can also be developed to handle temporary authentication failures and implement a mechanism to prevent brute force attacks, such as limiting the number of failures or implementing progressive delays. The retry policy is used to handle temporary authentication failure situations, such as those caused by network problems or brief service interruptions. Specifically, after an authentication failure, an automatic attempt to re-authenticate is made. Especially for temporary problems such as network fluctuations, a reasonable retry interval can also be set to avoid overloading the system with overly frequent attempts. For example, the retry interval can be increased after each failure, gradually expanding the waiting time. During the retry process, feedback is provided to the user, such as "The system is attempting to log in again, please wait".
[0251] Preventing brute force attacks means preventing malicious users from cracking account passwords through brute force by restricting the number of attempts or increasing the delay. Specifically, after a certain number of authentication failures (such as 5 times), the account is temporarily locked to prevent further attempts. When the account is locked, the user is notified and instructions for unlocking the account are provided (for example, sending an unlock link to the user's registered email).
[0252] After each authentication failure, the delay time can be increased. For example, increase the delay by 10 seconds after each failure, so that the number of attempts will become slower and slower.
[0253] An upper limit value can be set, for example, the maximum delay is up to 5 minutes, to prevent the delay time from being too long and affecting the user experience.
[0254] After multiple failures, require the user to complete CAPTCHA verification to ensure that the operator is a human user rather than an automated attack tool.
[0255] Furthermore, this application also includes a certificate caching mechanism to reduce the overhead of repeated verification. By caching the verified certificates or authentication data, it is possible to avoid performing repeated verification operations each time authentication is performed. Specifically, the verification results of certificates, authentication information, or session data can be cached. Common caching technologies include in-memory caching, distributed caching (such as Redis), etc.; a reasonable cache expiration time can also be set to ensure the validity and security of the cached data. For example, the cached authentication results can be set from a few minutes to a few hours and adjusted according to specific requirements.
[0256] When the certificate or authentication information changes, update the cache to maintain data accuracy; when the cache expires or becomes invalid, re-perform the verification and update the cache.
[0257] Furthermore, the use of hardware acceleration (such as dedicated encryption hardware) can also be considered. Hardware acceleration can accelerate encryption and decryption operations by using dedicated hardware (such as encryption chips or encryption cards), improving the efficiency of the authentication process. Specifically, use a hardware encryption module (HSM, Hardware Security Module) to perform encryption operations, providing high performance and security; install a dedicated encryption card in the server to handle encryption and decryption tasks, reducing the burden on the main processor; integrate the hardware acceleration component into the authentication system to ensure compatibility with software components; optimize the encryption algorithm according to the hardware characteristics to improve the acceleration effect.
[0258] Furthermore, this application also includes a strategy for configuring concurrent processing of multiple authentication requests. This strategy can handle multiple authentication requests simultaneously, improving the system's throughput and response capabilities. Specifically, thread pool technology can be used to manage and schedule the threads for processing multiple authentication requests, improving the concurrent processing ability; an asynchronous processing mechanism can be adopted to allow the system to continue processing other requests while waiting for the authentication results, reducing the response time; a load balancer can be used to distribute authentication requests to multiple servers or processing units, evenly distributing the load; the processing capacity of the system can be expanded by adding more server instances or processing nodes.
[0259] Through the above solutions, a powerful digital certificate support and two-way authentication mechanism can be achieved. This method ensures that both communication parties can reliably verify each other's identities, while providing a solid foundation for subsequent secure communication. In actual implementation, factors such as scalability, interoperability, and user experience also need to be considered to ensure that the system can operate securely and efficiently in various complex network environments and usage scenarios; at the same time, continuous security assessment and update are also the keys to maintaining the security of the system.
[0260] Furthermore, this application also includes performance optimization and monitoring. Performance optimization includes hardware acceleration and optimization of the data packet processing flow.
[0261] Hardware acceleration improves the performance of the system, especially the efficiency of encryption operations, through dedicated hardware components (such as dedicated encryption chips), thereby reducing the burden on the CPU.
[0262] A dedicated encryption chip, such as an HSM, a hardware security module, is a hardware device specifically designed to accelerate encryption and decryption operations.
[0263] Specifically, integrate the encryption chip into the system to handle encryption and decryption tasks. In this way, all encryption operations will be processed by dedicated hardware instead of relying on the main CPU; according to the capabilities of the encryption chip, select and optimize suitable encryption algorithms to improve the speed and efficiency of encryption operations.
[0264] A dedicated encryption chip processes encryption tasks faster than a general-purpose CPU, significantly improving the encryption efficiency of the system. Transferring the encryption tasks to dedicated hardware reduces the occupancy of the main CPU and frees up resources to handle other tasks.
[0265] Optimization of the data packet processing flow aims to improve the processing speed of data packets and reduce the processing burden on the CPU, especially when processing network data packets. Specifically, use a network interface card (NIC) or other hardware acceleration components to offload the data packet processing tasks from the main CPU to dedicated hardware; optimize the data packet reception, processing, and sending processes to reduce the CPU processing time. For example, process multiple data packets at once through batch processing technology to reduce processing latency; use caches (such as memory caches) to reduce frequent access to storage or the network, further improving the data packet processing efficiency.
[0266] Monitoring can be based on a performance monitoring module, which can be used to monitor the performance of the system in real time, including the throughput and latency of encryption operations, and provide performance reports and an alarm mechanism.
[0267] Preferably, the encryption throughput and latency can be monitored in real time. Specifically, monitoring tools or custom scripts can be used to collect real-time performance data of encryption operations, such as throughput, latency, error rate, etc. These performance metrics can be displayed in real time through dashboards or monitoring interfaces, facilitating administrators to view and analyze the performance status of the system. Performance thresholds can be set, such as the maximum allowed latency or the minimum throughput, to promptly detect and handle performance bottlenecks.
[0268] A performance reporting and alerting mechanism can also be provided. Specifically, generate periodic (such as daily, weekly) performance reports, summarize data on metrics such as encryption throughput and latency, and analyze trends. At the same time, allow the generation of custom reports according to requirements to view data for specific time periods or specific performance metrics.
[0269] For the alerting mechanism, alert rules can be set to automatically send alert notifications (such as emails, text messages, or system notifications) when performance metrics exceed the preset thresholds. Suggestions or operation steps for handling alerts can be provided to help administrators quickly solve problems.
[0270] Furthermore, the present application also includes a compatibility and scalability design mechanism, aiming to ensure that the system can operate in different network environments and can be integrated with other systems through API interfaces.
[0271] This design mechanism can adapt to different network topologies. Among them, the network topology refers to the layout method of each device and node in the network. Adapting to different network topologies can ensure the normal operation of the system under various network settings.
[0272] Specifically, when designing the system architecture, different network topologies (such as star, ring, mesh, etc.) are considered to ensure that system components can be connected in different topologies. It can support multiple network protocols (such as TCP / IP, UDP, etc.) so that the system can be used in various network environments. A simple configuration interface can be provided to allow users to flexibly adjust system settings according to the specific network topology.
[0273] This design mechanism also supports virtual network environments (such as SDN, NFV). The virtual network environment refers to a network architecture using software-defined network (SDN) and network function virtualization (NFV) technologies. Supporting these environments can improve the flexibility and scalability of the system.
[0274] Specifically, design the system to support the SDN architecture, enabling dynamic configuration of network resources under centralized control. Ensure that the system can be deployed in an NFV environment, running network functions on standard hardware using virtualization technology. Provide management tools so that users can dynamically adjust virtual network resources to meet different requirements.
[0275] The design mechanism can provide API interfaces to facilitate integration and interaction with other systems, supporting system expansion and function integration.
[0276] Specifically, a RESTful API can be designed to facilitate integration with other systems.
[0277] A plugin mechanism can also be implemented to support function expansion, that is, allowing developers to add new functions or expand existing functions without modifying the system core.
[0278] Specifically, clear plugin interfaces can be designed so that third-party developers can develop their own plugins according to the interface specifications; plugin management tools can be provided to allow users to easily install, uninstall, and enable / disable plugins. At the same time, ensure the compatibility of plugins with the core system, and provide backward-compatible APIs and data structures.
[0279] Furthermore, the transparent encryption model also includes storm control strategies for maintaining network stability and preventing broadcast storms.
[0280] Specifically, before forwarding encrypted packets, analyze the traffic patterns in the network where the encrypted packets are located to determine the traffic types that induce storms;
[0281] Dynamically regulate based on the traffic types and storm control strategies;
[0282] The storm control strategies include one or more of rate limit strategies, token bucket algorithm strategies, leaky bucket algorithms, broadcast storm control strategies, multicast storm control strategies, and priority queue strategies.
[0283] The storm control strategies in the transparent encryption model help maintain network stability and prevent broadcast storms. These strategies can be dynamically adjusted according to the traffic patterns in the network where the encrypted packets are located, specifically including rate limiting, token bucket algorithms, leaky bucket algorithms, broadcast storm control, and multicast storm control, etc. By restricting specific types of traffic or adjusting their transmission rates, network congestion and crashes caused by overload can be effectively prevented; controlling and scheduling traffic can make more efficient use of network resources to ensure the timely transmission of critical data; prevent malicious attacks or unexpected broadcast storm events, protecting the network from unauthorized access or damage; the strategies can be adjusted according to real-time network traffic conditions to adapt to different network environments and application requirements, thereby improving the adaptability and flexibility of the system.
[0284] The comprehensive application of these strategies can effectively optimize network performance and security, ensuring the secure transmission and stable operation of encrypted data.
[0285] Furthermore, this application also includes: implementing a comprehensive error handling mechanism and logging system. This includes capturing and recording possible exception situations, as well as recording key events and statistical information; good error handling and logging are crucial for the maintainability and problem diagnosis of the system.
[0286] Specifically, Rate Limiting includes: preventing the network from being flooded with excessive traffic by restricting the sending rate of devices or applications, which can be applied to individual devices, specific services, or the entire network.
[0287] The Token Bucket Algorithm is a traffic shaping technique that allows network devices to send a certain number of data packets within a certain period of time. Tokens are generated at a fixed rate and placed in a bucket, and data packets need to consume tokens in the bucket when being sent. If there are insufficient tokens, the data packets will be delayed or discarded.
[0288] The Leaky Bucket Algorithm is another traffic shaping technique, similar to the token bucket, but tokens are generated at a fixed rate and gradually consumed. The leaky bucket can smooth out bursty traffic and reduce network congestion.
[0289] Broadcast storm control is used to limit broadcast traffic and prevent the occurrence of broadcast storms, which can be achieved through the broadcast suppression function on network devices.
[0290] Multicast storm control is used to limit multicast traffic and prevent the occurrence of multicast storms, which can be achieved through multicast rate limiting or multicast suppression functions.
[0291] By these methods, network traffic can be effectively controlled and managed, preventing the occurrence of network storms, thereby ensuring the stability and reliability of the network.
[0292] Furthermore, some encryption algorithms may require the length of the input data to be a multiple of a specific value. In this case, an appropriate padding mechanism needs to be implemented; the padding follows a standard protocol (such as PKCS7) to ensure that the encrypted data can be correctly decrypted.
[0293] In the field of encryption, "padding" is a technique used to ensure that the length of the data to be encrypted meets the requirements of a specific encryption algorithm. Many encryption algorithms, especially block encryption algorithms (such as AES), require the input data to be an integer multiple of the block size. If the data length is not an integer multiple of the block size, padding is needed to increase the data length to meet the requirements.
[0294] Specifically, the basic concepts of padding include block size and padding operation. The block size is the basic unit for the encryption algorithm to process data, usually a fixed-length byte. The padding operation specifically includes: adding extra bytes at the end of the data to ensure that the data length is an integer multiple of the block size.
[0295] PKCS7 is a commonly used padding standard proposed by RSA Laboratories. It ensures that the padded data block can be correctly decrypted, and the padded data can be identified and removed.
[0296] The basic steps of the PKCS7 padding mechanism are as follows: 1) Determine the padding length: Calculate the number of bytes to be padded. Assume the block size is b and the original data length is l, then the padding length p can be calculated by the following formula: p = b - (l % b); where, % represents the modulo operation.
[0297] 2) Pad the data: Add bytes with the value of the padding length p to the end of the data. The value of the padded byte is the padding length itself.
[0298] 3) Remove padding during decryption: After decryption, by identifying the value of the padded byte, remove the corresponding padded byte to restore the original data.
[0299] Examples include: Assume the block size is 16 bytes (128 bits) and the original data length is 15 bytes. Then the padding length p = 16 - (15 % 16) = 1; pad one byte with the value of 1.
[0300] During decryption, identify that the padded byte is 1, remove one padded byte, and restore the original 15-byte data.
[0301] In this way, the length of the encrypted data can be adjusted to meet the requirements of the encryption algorithm, while ensuring that the original data can be correctly restored during decryption.
[0302] Furthermore, in an IP packet, the main thing that needs to be updated is the IP header checksum. In addition, if the packet contains upper-layer protocols (such as TCP or UDP), the checksums of these protocols may also need to be recalculated. The system needs to identify all the checksum fields that need to be updated.
[0303] Before starting to calculate the new checksum, the original checksum field needs to be cleared to zero. This is because the checksum calculation process requires these fields to be zero to obtain the correct result.
[0304] The calculation of the IP header checksum involves adding up all the 16-bit words in the IP header and then taking the one's complement. This process needs to consider the endianness (big-endian or little-endian) issue. Note that the header length may change due to IP options during the calculation.
[0305] If the data packet contains upper-layer protocols such as TCP or UDP, the calculation of the checksum for these protocols usually involves some fields in the IP header (such as source IP, destination IP), protocol-specific headers, and the data payload. Since the data payload has been encrypted, the calculation of this checksum becomes complex. There are several possible handling methods:
[0306] Recalculate the checksum completely, including the encrypted data.
[0307] Use an incremental update method to only calculate the impact of the changed parts.
[0308] In some cases, it may be necessary to set the checksum field of the upper-layer protocol to a fixed value or all zeros and rely on the error detection mechanism at the link layer.
[0309] After the calculation is completed, write the new checksum value into the corresponding field. For the IP header checksum, directly update the corresponding field in the IP header. For the upper-layer protocol checksum, it may be necessary to locate YY+242200P in the encrypted data payload
[0310] and update these fields.
[0311] After updating the checksum, perform verification to ensure the calculation is correct. This can be done by recalculating the checksum and comparing it with the updated value. This step helps to capture potential errors and ensure the integrity of the data packet.
[0312] Some special cases may require additional consideration, such as: the checksum calculation when processing IP options, the checksum update strategy when processing fragmented data packets, and the checksum handling when dealing with protocols with special requirements (such as ICMP).
[0313] Through these detailed steps, the encrypted data payload can be effectively recombined with the original IP header information, and all relevant checksum fields can be correctly updated. This process ensures the integrity and validity of the encrypted data packet while maintaining compatibility with the existing network infrastructure. In actual implementation, performance optimization, error handling, and management of exceptional situations also need to be considered to ensure that the system can operate efficiently and reliably under various network conditions.
[0314] The data security protection method based on link-layer transparent encryption disclosed in this application, since it is implemented at the link layer, ensures the real-time nature of data encryption processing, that is, the data is encrypted as soon as it is captured, reducing the exposure risk of data during transmission; through promiscuous mode capture and precise filtering, it avoids the performance loss caused by encrypting the entire network traffic and improves the overall efficiency of the system; uses a preset encryption algorithm and key to encrypt the data, ensuring the confidentiality of the data, and only authorized recipients can decrypt and read the data.
[0315] Example 1: Applying link - layer transparent encryption in the enterprise intranet environment. For example, a large enterprise needs to improve the security of internal data transmission without changing the existing network architecture. By adopting this technical solution, transparent encryption devices can be deployed at key nodes in the enterprise intranet. The specific implementation steps include: 1) Deploy a transparent encryption device between the core switch and department switches in the enterprise intranet; 2) Configure the two network interfaces of the encryption device, one connected to the core switch and the other to the department switch; 3) Enable promiscuous mode to capture all packets passing through this link; 4) Filter the captured packets to identify the business data that needs to be encrypted; 5) Use the AES256 algorithm to encrypt the data payload while keeping the IP header information unchanged; 6) Forward the encrypted packets to the target interface.
[0316] Through this deployment method, the enterprise can achieve encryption protection for sensitive data without affecting the existing network structure and applications. Employees do not need to perform any additional operations, and all encryption processes are completely transparent to them.
[0317] Example 2: Implementing transparent encryption in the cloud computing environment. For example, a cloud service provider hopes to provide additional data security guarantees for customers without affecting the performance and availability of existing cloud services. By adopting this technical solution, transparent encryption can be implemented in the virtual network environment. The specific implementation steps include: 1) Integrate a transparent encryption function module into the management platform of the virtual network; 2) Allocate independent encryption instances for each customer's virtual network; 3) Configure encryption policies at the entrances and exits of the virtual network to define the types of traffic that need to be encrypted; 4) Use virtualization technology to achieve efficient packet capture and processing; 5) Use hardware acceleration technology (such as Intel AESNI) to improve encryption efficiency; 6) Implement dynamic key management and update the encryption key regularly.
[0318] In this way, the cloud service provider can provide end - to - end data encryption services for customers while maintaining the high performance and flexibility of cloud services. Customers can easily configure and manage encryption policies through the control panel without modifying their application programs or network configurations.
[0319] Example 3: Applying link - layer transparent encryption in the Internet of Things scenario. For example, in the intelligent factory environment, it is necessary to protect the sensitive data generated by a large number of IoT devices. Since these devices usually have limited computing power and it is difficult to implement complex encryption algorithms, by adopting this technical solution, secure data transmission can be achieved without increasing the device burden.
[0320] The specific implementation steps include: 1) Integrate a transparent encryption module in the IoT gateway device; 2) Configure the IoT gateway so that it can identify and classify different types of IoT device data; 3) For sensitive data that needs to be protected, such as production parameters, device status, etc., enable transparent encryption; 4) Use a lightweight encryption algorithm (such as ChaCha20) for data encryption to meet the low-latency requirements of the IoT environment; 5) Implement a device authentication mechanism to ensure that only authorized devices can access the network; 6) Provide centralized key management to simplify the security management of large-scale IoT deployments.
[0321] Through this solution, the smart factory can significantly improve the security of data transmission without upgrading existing IoT devices. At the same time, since the encryption process is carried out at the gateway, it will not increase the computational burden on IoT devices, ensuring the real-time performance and reliability of the system.
[0322] These examples demonstrate the application flexibility and effectiveness of this technical solution in different scenarios. Whether in traditional enterprise networks, cloud computing environments, or emerging IoT fields, the transparent encryption technology based on the link layer can provide efficient and seamless data security protection while maintaining good compatibility with existing systems.
[0323] Referring to Figure 7 , the second aspect of this application discloses a data security protection system based on link layer transparent encryption, including:
[0324] A setting module 11, configured to determine several network interfaces of the configured transparent encryption model based on a configuration file or user input information, and set the modes of the several network interfaces to promiscuous mode;
[0325] A filtering module 12, configured to start the promiscuous mode, capture all raw packets passing through the target link based on the transparent encryption model, and filter the raw packets to obtain several raw packets that need to be encrypted, denoted as several first packets;
[0326] An obtaining module 13, configured to parse the first packet based on the transparent encryption model to obtain the information of the IP header;
[0327] A determining module 14, configured to determine the starting position and length of the IP packet data payload based on the information of the IP header, and determine the target data payload based on the starting position and length;
[0328] An encryption module 15, configured to encrypt the target data payload based on a preset encryption algorithm and an encryption key to obtain an encrypted data payload;
[0329] An updating module 16, configured to dynamically update the information of the IP header based on the encrypted data payload;
[0330] The recombination module 17 is configured to recombine the information of the updated IP header and the encrypted data payload into an encrypted data packet, and forward the encrypted data packet to the target interface.
[0331] The computer device according to an embodiment of the present disclosure includes a memory and a processor. The memory is used to store non - transient computer - readable instructions. Specifically, the memory may include one or more computer program products, and the computer program products may include various forms of computer - readable storage media, such as volatile memory and / or non - volatile memory. The volatile memory may include, for example, random access memory (RAM) and / or cache memory. The non - volatile memory may include, for example, read - only memory (ROM), hard disk, flash memory, etc.
[0332] The processor may be a central processing unit (CPU) or other forms of processing units with data - processing capabilities and / or instruction - execution capabilities, and may control other components in the computer device to perform desired functions. In an embodiment of the present disclosure, the processor is used to run the computer - readable instructions stored in the memory, so that the computer device executes all or part of the steps of the data security protection method based on link - layer transparent encryption in the foregoing embodiments of the present disclosure.
[0333] Those skilled in the art should understand that, in order to solve the technical problem of how to obtain good user experience effects, the embodiments may also include well - known structures such as communication buses, interfaces, etc., and these well - known structures should also be included in the protection scope of the present disclosure.
[0334] As Figure 8 FIG. is a schematic structural diagram of a computer device provided by an embodiment of the present disclosure. It shows a schematic structural diagram of a computer device suitable for implementing the computer device in the embodiments of the present disclosure. Figure 8 The shown computer device is only an example, and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.
[0335] As Figure 8 As shown, the computer device may include a processor (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in the read - only memory (ROM) or a program loaded from a storage device into the random access memory (RAM). In the RAM, various programs and data required for the operation of the computer device are also stored. The processor, ROM, and RAM are connected to each other through a bus. The input / output (I / O) interface is also connected to the bus.
[0336] Typically, the following devices can be connected to the I / O interface: input devices including, for example, sensors or visual information acquisition devices; output devices including, for example, display screens; storage devices including, for example, magnetic tapes, hard disks, etc.; and communication devices. The communication device can allow the computer device to communicate wirelessly or wiredly with other devices (such as edge computing devices) to exchange data. Although Figure 8 a computer device with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. More or fewer devices can be alternatively implemented or had.
[0337] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device, or installed from the ROM. When the computer program is executed by the processor, all or part of the steps of the data security protection method based on link layer transparent encryption according to the embodiments of the present disclosure are executed.
[0338] For a detailed description of this embodiment, reference can be made to the corresponding descriptions in the foregoing embodiments, and details are not repeated here.
[0339] A computer-readable storage medium according to an embodiment of the present disclosure stores non-temporary computer-readable instructions. When the non-temporary computer-readable instructions are run by the processor, all or part of the steps of the data security protection method based on link layer transparent encryption according to the foregoing embodiments of the present disclosure are executed.
[0340] The above-mentioned computer-readable storage media include but are not limited to: optical storage media (such as CD-ROMs and DVDs), magneto-optical storage media (such as MOs), magnetic storage media (such as magnetic tapes or removable hard disks), media with built-in rewritable non-volatile memories (such as memory cards), and media with built-in ROMs (such as ROM cartridges).
[0341] For a detailed description of this embodiment, reference can be made to the corresponding descriptions in the foregoing embodiments, and details are not repeated here.
[0342] The basic principles of the present disclosure have been described in connection with specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present disclosure are only examples and not limitations. It cannot be considered that these advantages, benefits, effects, etc. are essential for each embodiment of the present disclosure. Additionally, the specific details disclosed above are only for illustrative purposes and for ease of understanding, rather than limitations. The above details do not limit the present disclosure to necessarily adopt the above specific details for implementation.
[0343] In the present disclosure, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. The block diagrams of devices, apparatuses, equipment, and systems involved in the present disclosure are only illustrative examples and do not intend to require or imply that they must be connected, arranged, and configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, equipment, and systems can be connected, arranged, and configured in any manner. Words such as "including", "comprising", "having", etc. are open-ended terms, meaning "including but not limited to", and can be used interchangeably with each other. The word "or" and "and" used herein refer to the word "and / or", and can be used interchangeably with each other, unless the context clearly indicates otherwise. The word "such as" used herein refers to the phrase "such as but not limited to", and can be used interchangeably with each other.
[0344] In addition, as used herein, the "or" used in the listing of items starting with "at least one" indicates a disjunctive listing, so that for example, the listing of "at least one of A, B, or C" means A or B or C, or AB or AC or BC, or ABC (i.e., A and B and C). Furthermore, the term "exemplary" does not mean that the described examples are preferred or better than other examples.
[0345] It should also be noted that in the systems and methods of the present disclosure, each component or each step can be decomposed and / or recombined. These decompositions and / or recombinations should be regarded as equivalent solutions of the present disclosure.
[0346] Various changes, substitutions, and alterations to the technologies described herein can be made without departing from the teachings defined by the appended claims. In addition, the scope of the claims of the present disclosure is not limited to the specific aspects of the processes, machines, manufactures, compositions of events, means, methods, and acts described above. Current or later-developed processes, machines, manufactures, compositions of events, means, methods, or acts that perform substantially the same function or achieve substantially the same result as the corresponding aspects described herein can be utilized. Accordingly, the appended claims include such processes, machines, manufactures, compositions of events, means, methods, or acts within their scope.
[0347] The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the present disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein may be applied to other aspects without departing from the scope of the present disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0348] The above description has been presented for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of the present disclosure to the forms disclosed herein. Although several example aspects and embodiments have been discussed above, those skilled in the art will recognize some of their variations, modifications, alterations, additions, and subcombinations.
Claims
1. A data security protection method based on link layer transparent encryption, characterized in that, Including: Configuring a number of network interfaces with a transparent encryption model and setting the modes of the number of said network interfaces to promiscuous mode; Starting the promiscuous mode, capturing original data packets passing through the target link based on the transparent encryption model, and filtering the original data packets to obtain a number of original data packets to be encrypted, denoted as a number of first data packets; Parsing the first data packet based on the transparent encryption model to obtain information of the IP header; Determining the starting position and length of the IP packet data payload based on the information of the IP header, and determining the target data payload based on the starting position and the length; Encrypting the target data payload based on a preset encryption algorithm and an encryption key to obtain an encrypted data payload; Dynamically updating the information of the IP header based on the encrypted data payload; Recombining the updated information of the IP header and the encrypted data payload into an encrypted data packet, and forwarding the encrypted data packet to a target interface; The transparent encryption model includes a data packet capture policy, a data packet filtering policy, a data packet parsing policy, a data packet encryption policy, and a forwarding policy; the data packet capture policy includes capture filter information, capture buffer size information, capture mode information, size information of the data packet to be captured, and a preset function; the dynamically updating the information of the IP header based on the encrypted data payload includes: Changing the total length of the IP header based on the encrypted data payload, and the sum of the total length of the changed IP header and the total length of the encrypted data payload is consistent with the total length of the original data packet; Updating the checksum of the IP header based on the changed total length of the IP header to obtain an updated IP header.
2. The data security protection method based on link layer transparent encryption according to claim 1, characterized in that, The recombining the updated information of the IP header and the encrypted data payload into an encrypted data packet includes: Configuring a recombination buffer, the size of the recombination buffer is not less than the sum of the size of the updated IP header and the size of the encrypted data payload; Recombining the updated IP header and the encrypted data payload in the recombination buffer to obtain an encrypted data packet.
3. The data security protection method based on link layer transparent encryption according to claim 2, characterized in that, The recombining the updated IP header and the encrypted data payload in the recombination buffer to obtain an encrypted data packet includes: Copying the updated IP header to the starting position of the recombination buffer; Placing the encrypted data payload after the copied position of the updated IP header, and the setting position of the encrypted data payload is adjacent to the copied position of the updated IP header.
4. The data security protection method based on link layer transparent encryption according to claim 3, wherein, Also including: Adding metadata during the encryption process, the metadata includes one or more of an initialization vector, an authentication tag; The size of the recombination buffer is not less than the sum of the size of the updated IP header, the size of the encrypted data payload, and the size of the metadata; In the recombination buffer, the copying position of the metadata is between the copied position of the updated IP header and the setting position of the encrypted data payload; 5. The data security protection method based on link layer transparent encryption according to claim 4, characterized in that, If the original data packet is a fragment, updating the fragment offset based on the size of the encrypted data packet; If the encrypted data packet needs to be fragmented for transmission, the encrypted data packet is split into several blocks, and the fragment offset and more fragment flags of each block are updated.
6. The data security protection method based on link layer transparent encryption according to claim 1, characterized in that The preset encryption algorithm includes the AES algorithm or the ChaCha20 algorithm; The method for obtaining the encryption key includes: Determining the initial parameters of the preset key negotiation mechanism; Obtaining the local key pair of each communication party based on the initial parameters, where the local key pair includes a local private key and a local public key; Exchanging the local public keys of each communication party based on the preset security protocol; Obtaining a shared key based on the local private key and the public key of the other party; the public key of the other party is the local public key sent by the exchanging party received by the communication party corresponding to the local public key; Generating an encryption key from the shared key using a key derivation function.
7. The data security protection method based on link layer transparent encryption according to claim 6, characterized in that, The exchanging of the local public keys of each communication party based on the preset security protocol includes: Determining the certificate information of the digital certificate, where the certificate information includes the certificate standard, certificate format, certificate chain information, certificate verification mechanism, and certificate storage mechanism; Formulating a two-way authentication protocol policy based on the certificate information; Performing identity authentication on the first end and the second end based on the two-way authentication protocol policy and the certificate information. After passing the identity authentication, exchanging the local public keys of each communication party based on the preset security protocol; The first end is the first communication party, and the second end is the second communication party to perform public key exchange.
8. The data security protection method based on link layer transparent encryption according to any one of claims 1-7, characterized in that The transparent encryption model further includes a storm control policy; Before forwarding the encrypted data packet, analyzing the traffic pattern in the network where the encrypted data packet is located to determine the traffic type that induces storms; Performing dynamic regulation based on the traffic type and the storm control policy; The storm control policy includes one or more of a rate limit policy, a token bucket algorithm policy, a leaky bucket algorithm, a broadcast storm control policy, a multicast storm control policy, and a priority queue policy.
Citation Information
Patent Citations
Communication link safety reinforcement method
CN110752921A
End-to-end transparent transmission encryption method and device
CN115118503A