Hot standby switching method for satellite ground cipher machine and cipher machine
By employing a dedicated router and DPDK data plane suite in the satellite ground cryptographic machine, and utilizing MAC address and VLAN information for data transmission, high-performance and reliable hot switching of the primary and backup cryptographic machines is achieved. This solves the problem that keepalived based on IP address cannot effectively detect in existing technologies, and improves network performance and availability.
Patent Information
- Application Number
- CN202510131842.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-06
- Publication Date
- 2025-10-28
- Estimated Expiration
- 2045-02-06
AI Technical Summary
In existing technologies, the dual-machine hot standby operation of satellite ground cryptographic machines cannot effectively detect the primary and backup cryptographic machines based on IP address keepalived, resulting in insufficient reliability of data synchronization and hot switching. Especially in the DPDK-based environment, the primary and backup cryptographic machines cannot receive business data simultaneously.
By employing a dedicated router and DPDK data plane suite in the satellite ground cryptographic machine, data link layer communication between the primary and backup cryptographic machines is achieved. Data transmission is carried out using MAC addresses and VLAN information. Combined with a dedicated link and a promiscuous network card mode, hot switching between the primary and backup cryptographic machines is realized, avoiding IP address and application layer protocol processing.
It achieves high-performance data throughput and reliable hot switching between primary and backup cryptographic machines, reduces network broadcast storms and CPU load, improves network performance and availability, and ensures seamless switching of user business data.
Smart Images

Figure CN119602856B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a hot standby switching method for a satellite ground cryptographic machine and the cryptographic machine itself. Background Technology
[0002] The satellite-based ground cryptographic unit interacts with onboard security equipment to encrypt and decrypt user business data. The ground cryptographic unit is connected upstream to a dedicated satellite router with protocol stack data link layer forwarding capabilities. The two devices exchange data via private protocol calls. The cryptographic unit does not need to parse application layer protocols; it encrypts and decrypts data using MAC (Media Access Control) addresses, VLAN (Virtual Local Area Network) information, and key policies. To improve data encryption and decryption performance, the ground cryptographic unit utilizes the DPDK (Data Plane Development Kit) user-space layer for high-performance data throughput and processing, while also incorporating a dedicated cryptographic chip to enhance the overall efficiency of cryptographic applications.
[0003] When cryptographic devices malfunction during operation, preventing normal business cryptographic functions, a dual-machine hot standby function is required. If necessary, the backup cryptographic machine actively performs a hot switchover of data and functions from the master cryptographic machine, allowing users to seamlessly experience the device failure and maintain complete operation. Most devices perform dual-machine hot standby based on keepalived (software that detects server status) using IP addresses. Keepalived operates at the network, transport, and application layers of the TCP / IP protocol stack, detecting master cryptographic machine failures and performing a switchover through methods such as sending ICMP (a sub-protocol of the TCP / IP protocol suite, primarily used for transmitting control messages between the IP master cryptographic machine and routers) packets or port scanning techniques.
[0004] The ground-based cryptographic machine is developed based on the DPDK data plane suite. Business data is processed at network layer 2, without involving IP address and port settings or application layer protocol processing. In existing technologies, DPDK-based primary and backup cryptographic machines cannot simultaneously receive business data; MAC address-based primary and backup cryptographic machines cannot effectively detect each other; and the reliability of data synchronization and hot-switching between MAC address-based primary and backup cryptographic machines is insufficient. Summary of the Invention
[0005] The technical problem to be solved by the present invention is to provide a hot standby switching method and a cipher machine for satellite ground cipher machines, so as to realize the hot switching function of primary and backup ground cipher machines communicating with satellite cipher machines.
[0006] To solve the above-mentioned technical problems, the technical solution of the present invention is as follows:
[0007] A hot standby switching method for a satellite-to-ground cryptographic machine, applied to a first ground cryptographic machine, the method comprising:
[0008] The first ground cryptographic device receives first data information sent by ground equipment through a dedicated router. The first data information is sent from the satellite cryptographic device to the ground equipment.
[0009] After parsing the first data information and performing calculations according to a preset key strategy, the first ground cryptographic machine obtains the first return data, encapsulates the key strategy, and returns it to the satellite cryptographic machine through a dedicated router and ground equipment; and synchronizes the key strategy with the second ground cryptographic machine; wherein, the second ground cryptographic machine communicates with the ground equipment through the dedicated router and communicates with the first ground cryptographic machine through a dedicated link;
[0010] If the first ground cryptographic machine malfunctions and does not respond to the probe message from the second ground cryptographic machine within a preset time, the system switches to the second ground cryptographic machine. The second ground cryptographic machine receives the second data information forwarded by the ground equipment through a dedicated router, processes the second data information according to the preset key policy, obtains the second return data, and returns it to the satellite cryptographic machine through the dedicated router and the ground equipment. The second data information is sent from the satellite cryptographic machine to the ground equipment.
[0011] Optional hot standby switching methods for satellite ground cryptographic machines also include:
[0012] The first ground cryptographic device receives active probe messages sent by the second ground cryptographic device through the primary and backup probe ports;
[0013] The first ground cryptographic machine returns a probe response message to the second ground cryptographic machine based on the active probe message.
[0014] Optionally, if the first ground cipher machine malfunctions and does not respond to the probe message from the second ground cipher machine within a preset time, the system switches to the second ground cipher machine, including:
[0015] When the first ground cryptographic machine detects a fault in its own network card through the primary and backup detection ports, it determines that the first ground cryptographic machine has malfunctioned and sends fault information to the second ground cryptographic machine.
[0016] If no response is received from the second ground cipher machine within the preset time, the system will switch to the second ground cipher machine.
[0017] Optional hot standby switching methods for satellite ground cryptographic machines also include:
[0018] When the communication status of the first ground cryptographic machine is restored, a probe response message is returned to the second ground cryptographic machine.
[0019] Optionally, the primary and backup probe ports of the first ground cryptographic machine are connected to the second ground cryptographic machine via a dedicated router; or, the network card directly connected to the primary and backup probe ports of the first ground cryptographic machine is connected to the second ground cryptographic machine; the first ground cryptographic machine and the second ground cryptographic machine receive data by polling based on the data link layer MAC address of the data plane development kit, and the first ground cryptographic machine and the second ground cryptographic machine have the same virtual local area network label.
[0020] Optional hot standby switching methods for satellite ground cryptographic machines also include:
[0021] The first ground cryptographic device receives the target key policy sent by the second ground cryptographic device;
[0022] Update the local preset key policy according to the target key policy.
[0023] Embodiments of the present invention also provide a hot standby switching method for a satellite-to-ground cryptographic machine, applied to a second ground cryptographic machine that is communicatively connected to the first ground cryptographic machine via a dedicated link, the method comprising:
[0024] If the first ground cryptographic device malfunctions and does not respond to the probe message within a preset time, the second ground cryptographic device receives the second data information forwarded by the ground equipment through a dedicated router;
[0025] The second ground cryptographic machine processes the second data information according to a preset key strategy to obtain the second return data, and then returns it to the satellite cryptographic machine through a dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment.
[0026] Embodiments of the present invention also provide a first ground cipher machine, comprising:
[0027] The transceiver module is used to receive first data information sent by ground equipment through a dedicated router. The first data information is sent from the satellite cryptographic device to the ground equipment.
[0028] The processing module is used to parse the first data information, perform calculations according to a preset key policy to obtain first return data, encapsulate the key policy, and return it to the satellite cryptographic machine through a dedicated router and ground equipment; and synchronize the key policy with the second ground cryptographic machine; wherein, the second ground cryptographic machine communicates with the ground equipment through the dedicated router and communicates with the first ground cryptographic machine through a dedicated link; if the first ground cryptographic machine fails and does not reply with a probe message within a preset time, the system switches to the second ground cryptographic machine, which receives the second data information forwarded by the ground equipment through the dedicated router, performs calculations on the second data information according to the preset key policy to obtain second return data, and returns it to the satellite cryptographic machine through the dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment.
[0029] Embodiments of the present invention also provide a second ground cipher machine, comprising:
[0030] The transceiver module is used to receive second data information forwarded by the ground equipment through a dedicated router when the first ground cryptographic machine malfunctions and does not respond to the probe message within a preset time.
[0031] The processing module is used to perform calculations on the second data information according to a preset key policy, obtain the second return data, and return it to the satellite cryptographic machine through a dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment.
[0032] Embodiments of the present invention also provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method described above.
[0033] The above-described solution of the present invention has at least the following beneficial effects:
[0034] The above-described solution of the present invention involves a first ground cryptographic device receiving first data information sent by a ground device through a dedicated router. This first data information is sent from a satellite cryptographic device to the ground device. The first ground cryptographic device parses the first data information and performs calculations according to a preset key policy to obtain first return data. This first return data is then encapsulated with the key policy and returned to the satellite cryptographic device via the dedicated router and the ground device. The key policy is also synchronized with a second ground cryptographic device. The second ground cryptographic device is communicatively connected to the ground device through the dedicated router and to the first ground cryptographic device via a dedicated link. If the first ground cryptographic device malfunctions and does not respond to a probe message within a preset time, the second ground cryptographic device receives second data information forwarded by the ground device through the dedicated router, processes this second data information according to the preset key policy, obtains second return data, and returns it to the satellite cryptographic device via the dedicated router and the ground device. This achieves a hot-switching function between the primary and backup satellite ground cryptographic devices. Attached Figure Description
[0035] Figure 1 This is a flowchart illustrating the hot standby switching method for the satellite ground cryptographic machine of the present invention;
[0036] Figure 2 This is a schematic diagram of the master-slave communication structure of the cryptographic machine;
[0037] Figure 3 This is a schematic diagram of the primary and backup cryptographic machines probing using a router-based method;
[0038] Figure 4 This is a schematic diagram of the primary and backup cryptographic machines probing using a direct network interface card connection.
[0039] Figure 5 This is a schematic diagram of the hot-switching process for the primary and backup cryptographic machines. Detailed Implementation
[0040] Exemplary embodiments of the invention will now be described in more detail with reference to the accompanying drawings. While exemplary embodiments of the invention are shown in the drawings, it should be understood that the invention may be implemented in various forms and should not be limited to the embodiments set forth herein. Rather, these embodiments are provided so that this invention will be thorough and complete, and will fully convey the scope of the invention to those skilled in the art.
[0041] like Figure 1 As shown, an embodiment of the present invention provides a hot standby switching method for a satellite ground cryptographic machine, applied to a first ground cryptographic machine, the method comprising:
[0042] Step 11: The first ground cryptographic device receives first data information sent by the ground equipment through a dedicated router. The first data information is sent from the satellite cryptographic device to the ground equipment.
[0043] Step 12: The first ground cryptographic machine parses the first data information and performs calculations according to a preset key policy to obtain the first return data. After encapsulating the key policy, it returns the data to the satellite cryptographic machine through a dedicated router and ground equipment. The key policy is also synchronized with the second ground cryptographic machine. The second ground cryptographic machine communicates with the ground equipment through the dedicated router and with the first ground cryptographic machine through a dedicated link.
[0044] Step 13: If the first ground cryptographic machine malfunctions and does not respond to the probe message within a preset time, the system switches to the second ground cryptographic machine. The second ground cryptographic machine receives the second data information forwarded by the ground equipment through a dedicated router, processes the second data information according to the preset key policy, obtains the second return data, and returns it to the satellite cryptographic machine through the dedicated router and the ground equipment. The second data information is sent from the satellite cryptographic machine to the ground equipment.
[0045] In this embodiment of the invention, the satellite ground cryptographic machine interacts with the onboard security equipment to implement encryption and decryption functions for user service data. The above method enables hot-switching between primary and backup ground cryptographic machines during operation. Specifically, the first ground cryptographic machine (primary cryptographic machine) and the second ground cryptographic machine (backup cryptographic machine) achieve high-performance data throughput and processing based on the user-space layer of DPDK.
[0046] The first and second ground cryptographic machines are connected to a dedicated satellite router to forward data at the second layer of the network protocol stack. According to the requirements, user data is transmitted and processed at the data link layer based on MAC address, without the need for IP address and port settings.
[0047] The backup cipher machine and the primary cipher machine perform hot switching based on MAC address. The backup cipher machine needs to automatically start receiving user data forwarded by the dedicated router according to the switching trigger point.
[0048] To avoid router configuration or manual intervention, the backup cryptographic machine needs to be enabled in promiscuous mode, receiving all data packets passing through its network interface card (NIC), including data sent from the router to the primary cryptographic machine. The primary and backup cryptographic machines communicate via a dedicated link to continuously probe the primary cryptographic machine's status information, triggering a failover mechanism. When both the primary and backup machines are connected to the router port simultaneously, to reduce broadcast bursts and collisions, VLANs must be configured on the NICs of both the primary and backup machines using DPDK, along with VLAN hardware offloading to reduce the CPU load. VLAN configuration can divide a physical LAN into multiple logically independent virtual LANs. Isolating broadcast domains ensures that the probe link between the primary and backup cryptographic machines is unaffected by other networks, making it more independent and reliable, thus improving network performance and availability.
[0049] like Figure 2 As shown, the satellite cryptographic machine, along with the first and second ground cryptographic machines, are simultaneously connected to a dedicated ground router. The first ground cryptographic machine performs encryption and decryption operations on user data. Upon detecting a malfunction in the first ground cryptographic machine, the second ground cryptographic machine initiates its own encryption and decryption operations. The first and second ground cryptographic machines transmit probe information via a dedicated link to monitor the first ground cryptographic machine in real time for potential malfunctions, thereby determining whether the second ground cryptographic machine should take over the first ground cryptographic machine's functions.
[0050] Dedicated routers can be configured with VLAN information to isolate network communication and prevent flooding from affecting other network nodes. The password management system connects to the router, issuing key policies and management commands to the cryptographic device. User data devices forward encryption or decryption operations to the cryptographic device via the dedicated router. After completion, the terrestrial communication equipment transmits the data to the satellite system, where the satellite cryptographic device decrypts and forwards it to other applications.
[0051] The specific implementation process of the above method is as follows:
[0052] 1. The first and second ground cryptographic machines receive data (based on MAC address and promiscuous mode).
[0053] 2. The first ground-based cryptographic machine is developed based on the DPDK data plane suite. Business data is processed at the network layer 2, without involving IP address and port settings or application layer protocol processing. User business data is transmitted through a dedicated ground router, with source and destination MAC addresses configured, and the communication link is based on MAC address transmission.
[0054] The dedicated router determines the destination MAC address of the data packet to the master cryptographic machine based on the required rules, and performs port forwarding by searching the MAC table.
[0055] The first ground cryptographic machine receives and parses the business data and performs cryptographic operations according to the pre-defined key policy. After completion, it exchanges the source MAC and destination MAC addresses, encapsulates the key policy, and returns it through a dedicated router.
[0056] After the second ground cipher machine starts up, it does not receive service data by default. When it detects an anomaly in the first ground cipher machine by probing data packets, it automatically enables promiscuous mode on its network interface card (NIC) to receive all data packets passing through the NIC, including data not destined for the machine itself. Upon receiving user data forwarded to the first ground cipher machine by the router, it performs cryptographic calculations and then sends the completed data to the dedicated router according to the MAC address rules of the first ground cipher machine.
[0057] DPDK supports configuring promiscuous mode for network interface cards (NICs). Enabling promiscuous mode allows the NIC to receive all data streams passing through it, regardless of whether the destination MAC address is its own. By default, the NIC is in non-promiscuous mode, only able to receive data destined for itself or broadcast packets; other packets are discarded. The second ground cipher machine, which receives Layer 2 packets from the router and whose destination MAC address is not its own, needs to enable promiscuous mode on its NIC to receive and send data from the first ground cipher machine, thus enabling hot-swapping functionality.
[0058] In an optional embodiment of the present invention, the hot standby switching method for the satellite ground cryptographic machine further includes:
[0059] Step 14: The first ground cryptographic device receives the active probe message sent by the second ground cryptographic device through the primary and backup probe ports;
[0060] Step 15: The first ground cryptographic machine returns a probe response message to the second ground cryptographic machine based on the first probe message.
[0061] In an optional embodiment of the present invention, step 13, in the case that the first ground cipher machine malfunctions and does not respond to the probe message from the second ground cipher machine within a preset time, switches to the second ground cipher machine, including:
[0062] When the first ground cryptographic machine detects a fault in its own network card through the primary and backup detection ports, it determines that the first ground cryptographic machine has malfunctioned and sends fault information to the second ground cryptographic machine.
[0063] If no response is received from the second ground cipher machine within the preset time, the system will switch to the second ground cipher machine.
[0064] In an optional embodiment of the present invention, the hot standby switching method for the satellite ground cryptographic machine further includes:
[0065] Step 16: When the communication status of the first ground cryptographic machine is restored, a probe response message is returned to the second ground cryptographic machine.
[0066] In this embodiment, an independent detection port is set between the first ground cryptographic machine and the second ground cryptographic machine, which transmits and receives data based on MAC addresses and only transmits detection data.
[0067] There are two connection detection methods: connection based on a dedicated router and connection based on a direct network card.
[0068] When the primary and backup probe ports are connected to the router, data link layer forwarding is performed through MAC address-port mapping. To reduce Layer 2 network broadcasts, network crashes, and collisions, VLAN information needs to be configured to isolate communication within a virtual private LAN (VPN) from other networks. DPDK supports setting VLANs and adding or removing VLAN tags during packet processing. VLANs use tags to identify the virtual network to which a packet belongs, and DPDK can enable VLAN offload functionality, which is performed by the network interface card's hardware offload function, reducing the additional load on the CPU.
[0069] In this embodiment, the first ground cryptographic device has the function of actively triggering the detection of the status of its local service port. When the first ground cryptographic device actively triggers the detection that the local service port is in a down (fault) state, after failing to come up (go online or recover), the first ground cryptographic device actively sends status fault information to the second ground cryptographic device, so that the second ground cryptographic device enters the hot-swapping process.
[0070] The second ground cipher machine periodically checks the status of the first ground cipher machine for any abnormalities every N seconds (e.g., 1 second). Upon receiving the probe request, the first ground cipher machine returns to a normal state. If the second ground cipher machine does not receive a response from the first ground cipher machine within the predetermined timeout, the second ground cipher machine enters a hot-swap procedure.
[0071] In the above embodiments, such as Figure 3 The primary and backup detection ports of the first ground cryptographic device are connected to the second ground cryptographic device via a dedicated router; or, as... Figure 4 As shown, the network card directly connected to the primary and backup detection ports of the first ground cryptographic machine is connected to the second ground cryptographic machine for communication.
[0072] The first and second ground cryptographic machines receive data by polling the MAC address of the data link layer based on the data plane development kit. The first and second ground cryptographic machines have the same virtual local area network (VLAN) label.
[0073] In this embodiment, during normal operation, the first ground cryptographic machine (master cryptographic machine) receives key policy data or management instructions from the management system, saves and processes them, and simultaneously sends the data to the second ground cryptographic machine (backup cryptographic machine) in real time. This ensures that the backup cryptographic machine synchronizes its key policy and management instructions with the master cryptographic machine after a hot-swap. The backup cryptographic machine is pre-configured with the master cryptographic machine's MAC address and can normally receive policy data or management instructions from the master cryptographic machine. After successful verification, the data is saved without further processing.
[0074] After the backup cryptographic machine performs a hot-swap, it enters promiscuous mode and receives and processes key policy data or management commands normally. When the primary cryptographic machine returns to normal, the backup cryptographic machine immediately sends the received management data and key policies to the primary cryptographic machine to ensure that the key policy data or management commands of the primary and backup cryptographic machines are synchronized during operation.
[0075] Primary / standby hot-switch is a seamless process where the primary and standby cryptographic machines switch automatically based on triggering reasons without requiring device restarts or manual intervention, allowing users to operate without noticing the primary / standby system. The triggering point is either the primary cryptographic machine actively detecting anomalies in its local service ports, or the standby cryptographic machine actively detecting anomalies in the overall status of the primary cryptographic machine.
[0076] When performing a hot switch, the backup cryptographic machine starts the promiscuous mode of the network card, receives user data forwarded to the master cryptographic machine by the dedicated router, performs cryptographic calculations, and then forwards it to the router according to the master cryptographic machine address rules.
[0077] After the master cryptographic machine recovers, the backup cryptographic machine synchronizes the policy data to the master cryptographic machine, and at the same time disables the promiscuous mode of the network interface card and stops receiving user data. The master cryptographic machine then receives and processes user data normally.
[0078] based on Figure 3 and Figure 4 The communication method shown below describes the detection operation between the master and backup cipher machines as follows:
[0079] Master cryptographic machine actively triggers: The master cryptographic machine program actively triggers and probes the status of its local service ports. When a port status is abnormal, the master cryptographic machine sends a fault message through port probe, and the backup cryptographic machine enters the hot-swap process.
[0080] Backup cryptographic machine active probing: The backup cryptographic machine program sends probe data packets to the master cryptographic machine at regular intervals through the probe port. If no response probe packet is received from the master cryptographic machine within the timeout period, the backup cryptographic machine determines that the master cryptographic machine is abnormal and enters the hot switchover process.
[0081] The primary and backup cryptographic machines operate independently on their service ports and probe ports. Probe ports can forward data via a router or via direct NIC connection. When using router forwarding, VLANs need to be configured to reduce network broadcasts, network crashes, and conflicts, ensuring the probe link between the primary and backup cryptographic machines is unaffected by other networks, operating as a virtual private LAN, thus increasing link performance and reliability. With direct NIC connection, the probe physical link is independent, forwarding directly via the MAC addresses of the primary and backup cryptographic machines, unaffected by other networks, making the probe functionality of both machines more stable and reliable.
[0082] In an optional embodiment of the present invention, the hot standby switching method for the satellite ground cryptographic machine further includes:
[0083] Step 17: The first ground cryptographic device receives the target key policy sent by the second ground cryptographic device;
[0084] Step 18: Update the local preset key policy according to the target key policy.
[0085] like Figure 5 The following is an example of the implementation process of a specific embodiment of the present invention:
[0086] Connect the main cryptographic machine and backup cryptographic machine service ports to a dedicated ground router, and connect user business system equipment and management system equipment to a specific port of the router.
[0087] If you choose the router detection method, connect the primary and backup cryptographic machine detection ports to the dedicated router port. The router needs to be configured to allow VLAN IDs on both detection ports. If you choose the direct NIC detection method, connect the primary and backup cryptographic machine detection ports directly to each other without configuring VLANs.
[0088] 1. Start the primary and backup cryptographic machines. Data is received via round-robin based on the MAC address at the DPDK data link layer; no IP address configuration is required. After successful startup, configure the primary / backup identifier, VLAN information, MAC address, port, etc. for each machine. Enable VLAN hardware offloading in DPDK, and use the same VLAN tag for both primary and backup machines.
[0089] 2. The master cryptographic machine is enabled to receive service data, management data, key policy data, and probe data. The dedicated router is configured with the master cryptographic machine's MAC address and port for forwarding user and management data, and forwards probe information based on the VLAN configuration of the master and backup cryptographic machine's probe ports. The master cryptographic machine sends the received management data and key policy data to the backup cryptographic machine for data synchronization during a hot switch. The master cryptographic machine performs encryption and decryption operations on user data according to the key policy. After the cryptographic operation is completed, it exchanges the source and destination MAC addresses and forwards the data to the destination device through the dedicated router.
[0090] 3. The master cryptographic machine initiates active triggering of port status probing. The master cryptographic machine program actively probes the link status of its local service ports to determine whether they are up or down. When the port is down, after multiple failed attempts to go up, it indicates that the local service port is malfunctioning and cannot send or receive service data. In this case, the master cryptographic machine triggers the sending of fault information to the probing port. When the service port is up, data transmission and reception are normal, and there is no need to send status information to the probing port.
[0091] 4. The backup cryptographic machine enables the function of detecting the status of the master cryptographic machine. The backup cryptographic machine sends status detection information to the master cryptographic machine through the detection port every 1 second, and the master cryptographic machine responds promptly to the detection packets. If configured as a router, a detection packet containing VLAN information is sent to avoid network flooding affecting network nodes. 1) If the backup cryptographic machine's detection program times out without receiving a response from the master cryptographic machine, it determines that the master cryptographic machine is abnormal. 2) If the backup cryptographic machine receives a self-abnormal detection packet actively sent by the master cryptographic machine, it determines that the master cryptographic machine is abnormal.
[0092] 5. After detecting an anomaly in the primary cryptographic machine through probe information, the backup cryptographic machine immediately initiates the process of taking over the primary cryptographic machine. 1) The backup cryptographic machine enables promiscuous mode on its network interface card (NIC), receiving all data packets passing through the NIC, including data not destined for the machine itself. 2) After enabling this mode, the backup cryptographic machine can receive service data forwarded by the router to the primary cryptographic machine, with the destination MAC address being the primary cryptographic machine's. 3) The backup cryptographic machine's cryptographic program performs cryptographic operations on the user data according to the key policy previously synchronized with the primary cryptographic machine. After completion, the source and destination MAC addresses are exchanged, and the data is forwarded through a dedicated router, completing the hot switch between the primary and backup cryptographic machines. At this time, the user is unaware that either the primary or backup cryptographic machine is performing cryptographic operations.
[0093] 6. After the master cryptographic machine returns to normal operation, the backup cryptographic machine receives a valid response to the probe packets it sent, indicating that the master cryptographic machine is in normal operation. At this time, the backup cryptographic machine synchronously forwards the key policy information it received to the master cryptographic machine, stops promiscuous mode, and ceases receiving business data. The master cryptographic machine then resumes normal user data reception and cryptographic operations.
[0094] The method described above solves the problem of dual-machine hot standby for data transmission and reception at the link layer based on DPDK, and the cryptographic machine can be extended to general-purpose devices. The combination of active probing by the primary cryptographic machine and timed probing by the backup cryptographic machine improves the scope and real-time performance of fault detection. By adding a VLAN tag to the probe port, it is isolated from the service network, management network, or other converged networks in the switch or router, maximizing the independence, effectiveness, and reliability of the probe link.
[0095] Embodiments of the present invention also provide a hot standby switching method for a satellite-to-ground cryptographic machine, applied to a second ground cryptographic machine that is communicatively connected to the first ground cryptographic machine via a dedicated link, the method comprising:
[0096] If the first ground cryptographic device malfunctions and does not respond to the probe message within a preset time, the second ground cryptographic device receives the second data information forwarded by the ground equipment through a dedicated router;
[0097] The second ground cryptographic machine processes the second data information according to a preset key strategy to obtain the second return data, and then returns it to the satellite cryptographic machine through a dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment.
[0098] This method is a second ground cipher machine-side method corresponding to the first ground cipher machine-side method. All implementations of the first ground cipher machine-side method are applicable to the second ground cipher machine-side method and can achieve the same technical effect.
[0099] Embodiments of the present invention also provide a first ground cipher machine, comprising:
[0100] The transceiver module is used to receive first data information sent by ground equipment through a dedicated router. The first data information is sent from the satellite cryptographic device to the ground equipment.
[0101] The processing module is used to parse the first data information, perform calculations according to a preset key policy to obtain first return data, encapsulate the key policy, and return it to the satellite cryptographic machine through a dedicated router and ground equipment; and synchronize the key policy with the second ground cryptographic machine; wherein, the second ground cryptographic machine communicates with the ground equipment through the dedicated router and communicates with the first ground cryptographic machine through a dedicated link; if the first ground cryptographic machine fails and does not reply with a probe message within a preset time, the system switches to the second ground cryptographic machine, which receives the second data information forwarded by the ground equipment through the dedicated router, performs calculations on the second data information according to the preset key policy to obtain second return data, and returns it to the satellite cryptographic machine through the dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment.
[0102] Optionally, the transceiver module is further configured to: receive active probe messages sent by the second ground cryptographic machine through the primary and backup probe ports; and return probe response messages to the second ground cryptographic machine based on the active probe messages.
[0103] Optionally, if the first ground cipher machine malfunctions and does not respond to the probe message from the second ground cipher machine within a preset time, the system switches to the second ground cipher machine, including:
[0104] When the first ground cryptographic machine detects a fault in its own network card through the primary and backup detection ports, it determines that the first ground cryptographic machine has malfunctioned and sends fault information to the second ground cryptographic machine.
[0105] If no response is received from the second ground cipher machine within the preset time, the system will switch to the second ground cipher machine.
[0106] Optionally, the transceiver module is further configured to return a probe response message to the second ground cryptographic machine when the communication state of the first ground cryptographic machine is restored.
[0107] Optionally, the primary and backup detection ports of the first ground cryptographic machine are connected to the second ground cryptographic machine via a dedicated router; or, the network card directly connected to the primary and backup detection ports of the first ground cryptographic machine is connected to the second ground cryptographic machine.
[0108] Optionally, the first and second ground cryptographic machines receive data by polling the MAC address of the data link layer based on the data plane development kit, and the first and second ground cryptographic machines have the same virtual local area network (VLAN) label.
[0109] Optionally, the transceiver module is further configured to: receive a target key policy sent by the second ground cryptographic machine; and update a local preset key policy according to the target key policy.
[0110] It should be noted that this device corresponds to the method on the first ground cipher machine side described above. All implementation methods in the above method embodiments are applicable to the embodiments of this device and can achieve the same technical effect.
[0111] Embodiments of the present invention also provide a second ground cipher machine, comprising:
[0112] The transceiver module is used to receive second data information forwarded by the ground equipment through a dedicated router when the first ground cryptographic machine malfunctions and does not respond to the probe message within a preset time.
[0113] The processing module is used to perform calculations on the second data information according to a preset key policy, obtain the second return data, and return it to the satellite cryptographic machine through a dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment.
[0114] It should be noted that this device corresponds to the method on the second ground cipher machine side described above. All implementation methods in the above method embodiments are applicable to the embodiments of this device and can achieve the same technical effect.
[0115] Embodiments of the present invention also provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method described above or the method described above.
[0116] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments of the invention herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of the invention.
[0117] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0118] In the embodiments provided by this invention, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.
[0119] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0120] In addition, each functional unit in each embodiment of the present invention may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0121] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.
[0122] Furthermore, it should be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of the present invention. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of the present invention can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve by using their basic programming skills after reading the description of the present invention.
[0123] Therefore, the object of the present invention can also be achieved by running a program or a set of programs on any computing device. The computing device can be a known general-purpose device. Therefore, the object of the present invention can also be achieved simply by providing a program product containing program code for implementing the method or apparatus. That is, such a program product also constitutes the present invention, and the storage medium storing such a program product also constitutes the present invention. Obviously, the storage medium can be any known storage medium or any storage medium developed in the future. It should also be noted that in the apparatus and method of the present invention, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent to the present invention. Furthermore, the steps for performing the above series of processes can naturally be performed in the order described, but are not necessarily required to be performed in chronological order. Some steps can be performed in parallel or independently of each other.
[0124] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A hot standby switching method for a satellite ground cryptographic machine, characterized in that, Applied to a first ground cipher machine, the method includes: The first ground cryptographic device receives first data information sent by ground equipment through a dedicated router. The first data information is sent from the satellite cryptographic device to the ground equipment. After parsing the first data information and performing calculations according to a preset key strategy, the first ground cryptographic machine obtains the first return data, encapsulates the key strategy, and returns it to the satellite cryptographic machine through a dedicated router and ground equipment; and synchronizes the key strategy with the second ground cryptographic machine; wherein, the second ground cryptographic machine communicates with the ground equipment through the dedicated router and communicates with the first ground cryptographic machine through a dedicated link; If the first ground cryptographic device malfunctions and does not respond to the probe message from the second ground cryptographic device within a preset time, the system switches to the second ground cryptographic device. The second ground cryptographic device receives the second data information forwarded by the ground equipment through a dedicated router, processes the second data information according to the preset key policy, obtains the second return data, and returns it to the satellite cryptographic device through the dedicated router and the ground equipment. The second data information is sent from the satellite cryptographic device to the ground equipment. The first ground cryptographic machine receives the first data information, parses it, and performs cryptographic operations according to a preset key policy. After completion, it exchanges the source MAC and destination MAC addresses, encapsulates the key policy, and returns it to the satellite cryptographic machine through a dedicated router. The second ground cryptographic machine does not receive service data by default after starting up. When the first ground cryptographic machine is found to be abnormal by detecting data packets, it automatically turns on the network card promiscuous mode and receives all data packets passing through the network card, including data that is not sent to the local machine. When it receives user data forwarded to the first ground cryptographic machine by the dedicated router, it performs cryptographic calculations and sends the completed data to the dedicated router according to the MAC address rules of the first ground cryptographic machine. The method further includes: The first ground cryptographic device receives active probe messages sent by the second ground cryptographic device through the primary and backup probe ports; The first ground cryptographic device returns a probe response message to the second ground cryptographic device based on the active probe message; The first ground cryptographic machine and the second ground cryptographic machine are equipped with independent detection ports, which are based on MAC address for sending and receiving, and only transmit detection data. Wherein, if the first ground cipher machine malfunctions and does not respond to the probe message from the second ground cipher machine within a preset time, the switch to the second ground cipher machine includes: When the first ground cryptographic machine detects a fault in its own network card through the primary and backup detection ports, it determines that the first ground cryptographic machine has malfunctioned and sends fault information to the second ground cryptographic machine. If no response to the probe message from the second ground cipher machine is received within the preset time, switch to the second ground cipher machine; The method further includes: When the communication status of the first ground cryptographic machine is restored, a probe response message is returned to the second ground cryptographic machine; The first ground cryptographic device receives the target key policy sent by the second ground cryptographic device; Update the local preset key policy according to the target key policy; The first and second ground cryptographic machines receive data by polling the MAC address of the data link layer based on the data plane development kit, and the first and second ground cryptographic machines have the same virtual local area network label.
2. The hot standby switching method for the satellite ground cryptographic machine according to claim 1, characterized in that, The primary and backup detection ports of the first ground cryptographic machine are connected to the second ground cryptographic machine via a dedicated router; or, the network card directly connected to the primary and backup detection ports of the first ground cryptographic machine is connected to the second ground cryptographic machine. The first and second ground cryptographic machines receive data by polling the MAC address of the data link layer based on the data plane development kit. The first and second ground cryptographic machines have the same virtual local area network (VLAN) label.
3. A hot standby switching method for a satellite ground cryptographic machine, characterized in that, The method, applied to a second ground cryptographic machine that communicates with a first ground cryptographic machine via a dedicated link, includes: If the first ground cryptographic device malfunctions and does not respond to the probe message within a preset time, the second ground cryptographic device receives the second data information forwarded by the ground equipment through a dedicated router. The second ground cryptographic device processes the second data information according to a preset key strategy to obtain the second return data, and then returns it to the satellite cryptographic device through a dedicated router and ground equipment; the second data information is sent from the satellite cryptographic device to the ground equipment. The second ground cryptographic machine does not receive service data by default after starting up. When the first ground cryptographic machine is found to be abnormal by detecting data packets, it automatically turns on the network card promiscuous mode and receives all data packets passing through the network card, including data that is not sent to the local machine. When it receives user data forwarded to the first ground cryptographic machine by the dedicated router, it performs cryptographic calculations and sends the completed data to the dedicated router according to the MAC address rules of the first ground cryptographic machine. The method further includes: The second ground cryptographic device sends active probe messages to the first ground cryptographic device through the primary and backup probe ports; The second ground cryptographic device receives the probe response message returned by the first ground cryptographic device based on the active probe message; The first ground cryptographic machine and the second ground cryptographic machine are equipped with independent detection ports, which are based on MAC address for sending and receiving, and only transmit detection data. In the event that the first ground cryptographic device malfunctions and fails to respond to a probe message within a preset time, the second ground cryptographic device receives second data information forwarded by the ground equipment through a dedicated router, including: The second ground cryptographic machine receives fault information; the fault information is sent by the first ground cryptographic machine to the second ground cryptographic machine when the first ground cryptographic machine detects a fault in its own network card through the primary and backup detection ports. If no response to the probe message is received from the first ground cryptographic machine within a preset time, the system switches to the second ground cryptographic machine. The method further includes: The second ground cryptographic device receives a probe response message; the probe response message is a probe response message returned to the second ground cryptographic device when the communication state of the first ground cryptographic device is restored. The second ground cryptographic device sends a target key policy to the first ground cryptographic device, causing the first ground cryptographic device to update its local preset key policy according to the target key policy. The first and second ground cryptographic machines receive data by polling the MAC address of the data link layer based on the data plane development kit, and the first and second ground cryptographic machines have the same virtual local area network label.
4. A first ground-based cipher machine, characterized in that, include: The transceiver module is used to receive first data information sent by ground equipment through a dedicated router. The first data information is sent from the satellite cryptographic device to the ground equipment. The processing module is used to parse the first data information, perform calculations according to a preset key policy to obtain first return data, encapsulate the key policy, and return it to the satellite cryptographic machine via a dedicated router and ground equipment; and synchronize the key policy with the second ground cryptographic machine; wherein the second ground cryptographic machine is communicatively connected to the ground equipment via the dedicated router and to the first ground cryptographic machine via a dedicated link; if the first ground cryptographic machine fails and does not reply with a probe message within a preset time, the system switches to the second ground cryptographic machine, which receives the second data information forwarded by the ground equipment through the dedicated router, performs calculations on the second data information according to the preset key policy to obtain second return data, and returns it to the satellite cryptographic machine via the dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment; The first ground cryptographic machine receives the first data information, parses it, and performs cryptographic operations according to a preset key policy. After completion, it exchanges the source MAC and destination MAC addresses, encapsulates the key policy, and returns it to the satellite cryptographic machine through a dedicated router. The second ground cryptographic machine does not receive service data by default after starting up. When the first ground cryptographic machine is found to be abnormal by detecting data packets, it automatically turns on the network card promiscuous mode and receives all data packets passing through the network card, including data that is not sent to the local machine. When it receives user data forwarded to the first ground cryptographic machine by the dedicated router, it performs cryptographic calculations and sends the completed data to the dedicated router according to the MAC address rules of the first ground cryptographic machine. The transceiver module is further used for: The active probe messages sent by the second ground cryptographic machine are received through the primary and backup probe ports; The active probe message is used to return a probe response message to the second ground cryptographic machine; The first ground cryptographic machine and the second ground cryptographic machine are equipped with independent detection ports, which are based on MAC address for sending and receiving, and only transmit detection data. Wherein, if the first ground cipher machine malfunctions and does not respond to the probe message from the second ground cipher machine within a preset time, the switch to the second ground cipher machine includes: When the first ground cryptographic machine detects a fault in its own network card through the primary and backup detection ports, it determines that the first ground cryptographic machine has malfunctioned and sends fault information to the second ground cryptographic machine. If no response to the probe message from the second ground cipher machine is received within the preset time, switch to the second ground cipher machine; The transceiver module is also used for: When the communication status of the first ground cryptographic machine is restored, a probe response message is returned to the second ground cryptographic machine; Receive the target key strategy sent by the second ground cryptographic machine; Update the local preset key policy according to the target key policy; The first and second ground cryptographic machines receive data by polling the MAC address of the data link layer based on the data plane development kit, and the first and second ground cryptographic machines have the same virtual local area network label.
5. A second ground cipher machine, characterized in that, include: The transceiver module is used to receive second data information forwarded by ground equipment through a dedicated router when the first ground cryptographic machine fails and does not respond to the probe message within a preset time. The processing module is used to perform calculations on the second data information according to a preset key policy, obtain second return data, and return it to the satellite cryptographic machine through a dedicated router and ground equipment; the second data information is sent from the satellite cryptographic machine to the ground equipment. The second ground cryptographic machine does not receive business data by default after starting up. When it is determined that the first ground cryptographic machine is abnormal by probing data packets, it automatically turns on the network card promiscuous mode and receives all data packets passing through the network card, including data that is not sent to the local machine. When it receives user data forwarded to the first ground cryptographic machine by the dedicated router, it performs cryptographic calculations and sends it to the dedicated router according to the MAC address rules of the first ground cryptographic machine. The transceiver module is also used for: Active probe messages are sent to the first ground cryptographic machine through the primary and backup probe ports; Receive the probe response message returned by the first ground cryptographic machine based on the active probe message; The first ground cryptographic machine and the second ground cryptographic machine are equipped with independent detection ports, which are based on MAC address for sending and receiving, and only transmit detection data. In the event that the first ground cryptographic device malfunctions and fails to respond to a probe message within a preset time, the second ground cryptographic device receives second data information forwarded by the ground equipment through a dedicated router, including: The second ground cryptographic machine receives fault information; the fault information is sent by the first ground cryptographic machine to the second ground cryptographic machine when the first ground cryptographic machine detects a fault in its own network card through the primary and backup detection ports. If no response to the probe message is received from the first ground cryptographic machine within a preset time, the system switches to the second ground cryptographic machine. The transceiver module is further used for: Receive probe response messages; the probe response messages are probe response messages returned to the second ground cryptographic machine when the communication state of the first ground cryptographic machine is restored; Send the target key policy to the first ground cryptographic machine; causing the first ground cryptographic machine to update its local preset key policy according to the target key policy; The first and second ground cryptographic machines receive data by polling the MAC address of the data link layer based on the data plane development kit, and the first and second ground cryptographic machines have the same virtual local area network label.
6. A computer-readable storage medium, characterized in that, A storage instruction that, when executed on a computer, causes the computer to perform the method as described in any one of claims 1 to 2 or the method as described in claim 3.
Citation Information
Patent Citations
PPP-B2b signal transmission method and system based on telegraph text service system
CN116192365A
Dual-computer hot-standby satellite-borne cryptographic equipment, main-standby switching method, satellite and communication system
CN119276328A