Network Interconnection Method, System, Storage Medium and Computer Based on Cluster Network
By generating and verifying the connection requests in the cluster network, the problems of instability in the security of the cluster network and information leakage are solved, and secure network interconnection and data confidentiality protection are achieved.
Patent Information
- Application Number
- CN202510252986.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-05
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-05
AI Technical Summary
The existing cluster network technology has instability in network security protection, and there are security vulnerabilities in data transmission between nodes, resulting in information leakage and resource loss.
By randomly generating verification keys in the cluster network, data verification is performed on the connection request, the initiator's connection private key and reception identifier are extracted, the session key is generated, and network interconnection is realized through message authentication code verification.
Improve network security, ensure data confidentiality through multiple verifications, and realize secure network interconnection between the initiator and the receiver to prevent information leakage.
Smart Images

Figure CN119743259B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network interconnection technologies, and particularly to a network interconnection method, system, storage medium, and computer based on a cluster network. Background Art
[0002] With the continuous development of information network technologies and the rapid improvement of people's living standards, cluster networks have become technologies frequently used in various industries, and can be applied to network connections between different nodes, thereby achieving the effect of collaborative work.
[0003] Currently, for cluster network technologies, traditional firewalls inside nodes are usually used to implement network security protection. This method lacks the effects of encryption and isolation for communication between internal nodes of the cluster network, resulting in instability in network security; moreover, corresponding components need to be installed on each node in the cluster network. If there are security vulnerabilities or lack of data verification in the components installed on each node during data transmission, all node information in the cluster network will be exposed, leading to the leakage of information of each node and causing resource loss. Summary of the Invention
[0004] Based on this, the purpose of the present invention is to provide a network interconnection method, system, storage medium, and computer based on a cluster network to at least solve the deficiencies in the above technologies.
[0005] The present invention provides a network interconnection method based on a cluster network, including:
[0006] When a connection request initiated by an initiator is obtained, a corresponding verification key is randomly generated according to the connection request;
[0007] Perform data verification on the verification key. If the data verification passes, extract the connection private key of the initiator and the corresponding receiving identifier from the connection request;
[0008] Determine the receiver according to the receiving identifier, and generate a corresponding session key by using the connection private key fed back by the receiver based on the verification key and the connection private key of the initiator;
[0009] Generate a message authentication code based on the session key, and verify the message authentication code. If the message authentication code verification passes, obtain the session parameters of the connection party based on the session key, generate a corresponding deployment strategy according to the session parameters, and use the deployment strategy to implement network interconnection between the initiator and the receiver.
[0010] Further, before the step of when a connection request initiated by an initiator is obtained, the method further includes:
[0011] Obtain the user information of all independent users in the cluster network, where the user information includes communication protocols, sending identifiers, and corresponding receiving identifiers;
[0012] Randomly generate corresponding connection keys according to the communication protocols of each independent user, and construct security control protocols corresponding to each independent user based on the connection keys and the communication protocols;
[0013] Define security communication protocols between each independent user by using each security control protocol, and construct virtual connections between each independent user based on the security communication protocols.
[0014] Further, the steps of performing data verification on the verification key, and if the data verification passes, extracting the connection private key of the initiator and the corresponding receiving identifier in the connection request include:
[0015] Perform a hash calculation on the verification key to obtain a corresponding hash attribute value, and verify the hash attribute value. If the hash attribute value verification passes, send a data verification passed signal;
[0016] Obtain the certificate chain of the initiator from the connection request, and obtain the connection private key of the initiator and the corresponding receiving identifier according to the certificate chain.
[0017] Further, the steps of determining the receiver according to the receiving identifier and generating a corresponding session key by using the connection private key fed back by the receiver based on the verification key and the connection private key of the initiator include:
[0018] Find the corresponding receiver among all independent users in the cluster network according to the receiving identifier, and use the key matrix algorithm to obtain the connection private key fed back by the receiver based on the verification key;
[0019] Generate an interaction data packet according to the connection private key fed back by the receiver based on the verification key and the connection private key of the initiator, and generate a corresponding session key by using the verification result of the interaction data packet.
[0020] Further, the steps of generating a message authentication code based on the session key and verifying the message authentication code include:
[0021] Parse the response time of the random number of the session key, determine whether the response time of the random number times out. If the response time of the random number does not time out, save the random number of the session key;
[0022] Generate a corresponding authentication data packet according to the random number of the session key, and authenticate the authentication data packet by using a preset handshake authentication algorithm to obtain a corresponding authentication result.
[0023] The present invention also provides a network interconnection system based on a cluster network, including:
[0024] A first verification module, configured to randomly generate a corresponding verification key according to the connection request when obtaining a connection request initiated by an initiator;
[0025] A second verification module, configured to perform data verification on the verification key. If the data verification passes, extract the connection private key of the initiator and the corresponding receiving identifier from the connection request;
[0026] A key generation module, configured to determine a recipient according to the receiving identifier, and generate a corresponding session key by using the connection private key fed back by the recipient based on the verification key and the connection private key of the initiator;
[0027] A network interconnection module, configured to generate a message authentication code based on the session key, and verify the message authentication code. If the message authentication code verification passes, obtain the session parameters of the connection party based on the session key, and generate a corresponding deployment policy according to the session parameters, and use the deployment policy to implement network interconnection between the initiator and the recipient.
[0028] Further, the system further includes:
[0029] An information acquisition module, configured to acquire user information of all independent users in the cluster network, where the user information includes a communication protocol, a sending identifier, and a corresponding receiving identifier;
[0030] A protocol generation module, configured to randomly generate a corresponding connection key according to the communication protocol of each independent user, and construct a security control protocol corresponding to each independent user based on the connection key and the communication protocol;
[0031] A virtual connection module, configured to define a secure communication protocol between each independent user by using each security control protocol, and construct a virtual connection between each independent user based on the secure communication protocol.
[0032] Further, the second verification module includes:
[0033] A hash verification unit, configured to perform a hash calculation on the verification key to obtain a corresponding hash attribute value, and verify the hash attribute value. If the hash attribute value verification passes, send a data verification passed signal;
[0034] A private key acquisition unit, configured to acquire the certificate chain of the initiator from the connection request, and acquire the connection private key of the initiator and the corresponding receiving identifier according to the certificate chain.
[0035] Further, the key generation module includes:
[0036] A data feedback unit, configured to find a corresponding recipient among all independent users of the cluster network according to the received identifier, and obtain a connection private key fed back by the recipient based on the verification key by using a key matrix algorithm;
[0037] A key generation unit, configured to generate an interaction data packet according to the connection private key fed back by the recipient based on the verification key and the connection private key of the initiator, and generate a corresponding session key by using a verification result of the interaction data packet.
[0038] Further, the network interconnection module includes:
[0039] A data parsing unit, configured to parse a response time of a random number of the session key, determine whether the response time of the random number times out, and if the response time of the random number does not time out, save the random number of the session key;
[0040] A handshake authentication unit, configured to generate a corresponding authentication data packet according to the random number of the session key, and authenticate the authentication data packet by using a preset handshake authentication algorithm to obtain a corresponding authentication result.
[0041] The present invention also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, the above network interconnection method based on a cluster network is implemented.
[0042] The present invention also provides a computer, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, the above network interconnection method based on a cluster network is implemented.
[0043] The network interconnection method, system, storage medium and computer based on a cluster network in the present invention randomly generate a verification key for the connection request initiated by the initiator, and perform data verification on the verification key. If the data verification passes, the connection private key and the receiving identifier of the initiator are extracted from the connection request; the receiver is determined using the receiving identifier, and the session key is generated by the receiver based on the connection private key fed back by the verification key and the connection private key of the initiator. The message authentication code generated by the session key is verified. If the message authentication code verification passes, the corresponding session parameters are obtained based on the session key, and the deployment policy is generated using the session parameters, thereby realizing the network interconnection between the initiator and the receiver. The network interconnection between the initiator and the receiver is realized through multiple verification methods, thereby improving network security. The confidentiality protection of data is realized by using the session key method. Identity authentication and key negotiation are performed before the connection between the initiator and the receiver components, thereby achieving the protection effect on network security. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] Figure 1 It is a flowchart of the network interconnection method based on a cluster network in the first embodiment of the present invention;
[0045] Figure 2 is Figure 1 a detailed flowchart of step S102 in
[0046] Figure 3 is Figure 1 a detailed flowchart of step S103 in
[0047] Figure 4 is Figure 1 a detailed flowchart of step S104 in
[0048] Figure 5 It is a structural block diagram of the network interconnection system based on a cluster network in the second embodiment of the present invention;
[0049] Figure 6 It is a structural block diagram of the computer in the third embodiment of the present invention.
[0050] The following specific embodiments will further illustrate the present invention in conjunction with the above-mentioned drawings. SPECIFIC EMBODIMENTS
[0051] To facilitate the understanding of the present invention, the present invention will be described more comprehensively below with reference to the relevant drawings. Several embodiments of the present invention are given in the drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. On the contrary, these embodiments are provided to make the disclosure of the present invention more thorough and comprehensive.
[0052] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this invention belongs. The terms used in the specification of the present invention are for the purpose of describing specific embodiments only and are not intended to limit the present invention. The term "and / or" used herein includes any and all combinations of one or more of the related listed items.
[0053] Embodiment 1
[0054] Please refer to Figure 1 , which shows the network interconnection method based on a cluster network in the first embodiment of the present invention. The method specifically includes steps S101 to S104:
[0055] S101, when a connection request initiated by the initiator is obtained, a corresponding verification key is randomly generated according to the connection request;
[0056] In this embodiment, a cluster network is a system in which multiple computers or servers are connected through an interconnected network and run specific software to manage these nodes, so as to work together to complete specific tasks. For example, all subsidiaries of a certain head office are connected through an interconnected network, so as to realize message transmission and corresponding data forwarding between subsidiaries. In this cluster network, all users (i.e., subsidiaries) are independent users.
[0057] In some alternative embodiments, before the above step S101, the method further includes the following steps:
[0058] Obtain the user information of all independent users in the cluster network, where the user information includes communication protocols, sending identifiers, and corresponding receiving identifiers;
[0059] Randomly generate corresponding connection keys according to the communication protocols of each independent user, and construct a security control protocol corresponding to each independent user based on the connection keys and the communication protocols;
[0060] Define the secure communication protocol between each independent user using each security control protocol, and construct a virtual connection between each independent user based on the secure communication protocol.
[0061] In specific implementation, user information of all independent users in the cluster network is obtained. The user information includes the communication protocol required for a certain independent user to connect with other independent users in the cluster network, the sending identifier required for sending relevant data files, and the receiving identifier of the receiving party for receiving the relevant data files. A connection key corresponding to each independent user's communication protocol is randomly generated using a key generation algorithm, which includes but is not limited to algorithms such as the DES algorithm, AES algorithm, RSA algorithm, ECC algorithm, and MD5 algorithm. The connection keys of each independent user and their corresponding communication protocols are combined to construct the security control protocol corresponding to each independent user.
[0062] In this embodiment, the security control protocol consists of a control code generated by a preset algorithm based on the user identifier in the user information, a connection key, and a protocol header for identifying and managing data. The above-mentioned sending identifier and receiving identifier are used to construct a virtual connection between each independent user. In the cluster network environment, a logical connection is established between each independent user, enabling users or nodes to communicate and transfer data with each other on the network without caring about the details of the underlying physical connection. Thus, when the physical connection changes (for example, the physical link between nodes is disconnected), independent users can still communicate through other paths, further improving the efficiency of network interconnection, ensuring the effective utilization of network resources, and providing reliable communication services for users.
[0063] Further, when a certain independent user needs to transfer a data file, it uploads a connection request as the initiator. The connection request contains the identifier information of the initiator, and a random verification key is generated for the identifier information of the initiator using a key random generation algorithm.
[0064] S102. Perform data verification on the verification key. If the data verification passes, extract the connection private key of the initiator and the corresponding receiving identifier from the connection request.
[0065] Further, please refer to Figure 2 , the step S102 specifically includes steps S1021 to S1022:
[0066] S1021. Perform a hash calculation on the verification key to obtain the corresponding hash attribute value, and verify the hash attribute value. If the hash attribute value verification passes, send a data verification passed signal.
[0067] S1022. Obtain the certificate chain of the initiator from the connection request, and obtain the connection private key of the initiator and the corresponding receiving identifier according to the certificate chain.
[0068] In specific implementation, perform a hash calculation on the obtained verification key to obtain the hash attribute value corresponding to the verification key. In this embodiment, the hash algorithm for the verification key adopts the SHA-256 algorithm. Verify the calculated hash attribute value. If the verified hash attribute value is the same as the hash attribute value before verification, mark the verification as passed and send a data verification passed signal.
[0069] Specifically, obtain the certificate chain of the initiator from the above connection request, parse the certificate chain, and thus extract the connection private key of the initiator and the receiving identifier corresponding to the connection request. The receiving identifier is the identifier corresponding to the receiver that the initiator wants to establish a connection with, and the connection private key is the private key generated by the initiator according to the connection request and used for the connection.
[0070] S103. Determine the receiver according to the receiving identifier, and generate a corresponding session key from the connection private key fed back by the receiver based on the verification key and the connection private key of the initiator.
[0071] Further, please refer to Figure 3 The step S103 specifically includes steps S1031 to S1032:
[0072] S1031. Find the corresponding receiver among all independent users in the cluster network according to the receiving identifier, and use the key matrix algorithm to obtain the connection private key fed back by the receiver based on the verification key.
[0073] S1032. Generate an interaction data packet from the connection private key fed back by the receiver based on the verification key and the connection private key of the initiator, and generate a corresponding session key using the verification result of the interaction data packet.
[0074] In specific implementation, find the corresponding receiver among all independent users in the cluster network according to the extracted receiving identifier, verify the SNI of the sender and the corresponding hash attribute value to prevent a strong computing attack. The sender selects a corresponding large prime number and a corresponding primitive root, selects a random integer as the connection private key, and uses the key matrix algorithm and a known mapping algorithm to calculate the above verification key, thereby obtaining the connection private key corresponding to the receiver.
[0075] Specifically, exchange according to the connection private key of the receiver and the connection private key of the initiator to generate a corresponding interaction data packet, encrypt the interaction data packet using the public key corresponding to the connection private key of the sender, and process the encrypted interaction data packet using a pseudo-random function. At the same time, verify the signature information of the receiver using the public key matrix and a known mapping algorithm, and combine the processing result and the verification result to obtain a corresponding session key.
[0076] S104. Generate a message authentication code based on the session key, and verify the message authentication code. If the message authentication code is verified successfully, obtain the session parameters of the connection party based on the session key, generate a corresponding deployment policy according to the session parameters, and use the deployment policy to realize the network interconnection between the initiator and the receiver.
[0077] Further, please refer to Figure 4 , the step S104 specifically includes steps S1041 to S1042:
[0078] S1041. Parse the response time of the random number of the session key, and determine whether the response time of the random number times out. If the response time of the random number does not time out, save the random number of the session key;
[0079] S1042. Generate a corresponding authentication data packet according to the random number of the session key, and authenticate the authentication data packet by using a preset handshake authentication algorithm to obtain a corresponding authentication result.
[0080] In specific implementation, parse the response time of the random number of the session key, and determine whether the response time of the random number times out. If the response time of the random number times out, ignore the connection request sent by the initiator. If the response time of the random number does not time out, save the random number of the session key, generate a corresponding authentication data packet according to the random number of the session key, and authenticate the authentication data packet by using a preset handshake authentication algorithm to obtain an authentication result;
[0081] Specifically, the initiator generates an authentication data packet for connection according to the session key, and the content includes the serial number of the initiator, the message type, and the identifiers of both parties. After receiving the authentication data packet, the receiver verifies the authenticity of the message type. If the message is true, the receiver generates a second authentication data packet, and the content includes the identifiers of both parties, the serial numbers of both parties, the message type, and the message authentication code generated by the receiver according to the session key. After receiving the second authentication data packet, the initiator verifies the message authentication code in its content. After the verification is passed, the initiator generates a third authentication data packet. When the receiver receives the third authentication data packet, obtain the corresponding session parameters from a preset database according to the session key, and obtain the corresponding deployment policy from the deployment policy library according to the session parameters, and use the deployment policy to realize the network interconnection between the initiator and the receiver.
[0082] In summary, in the above embodiments of the present invention, the network interconnection method based on a cluster network randomly generates a verification key for the connection request initiated by the initiator, and performs data verification on the verification key. If the data verification passes, the connection private key of the initiator and the receiving identifier are extracted from the connection request; the receiving party is determined using the receiving identifier, and the receiving party generates a session key based on the connection private key fed back by the verification key and the connection private key of the initiator, and verifies the message authentication code generated by the session key. If the message authentication code verification passes, the corresponding session parameters are obtained based on the session key, and a deployment strategy is generated using the session parameters, thereby realizing the network interconnection between the initiator and the receiving party. The network interconnection between the initiator and the receiving party is realized through multiple verification methods, thereby improving network security. The confidentiality protection of data is realized by using the session key method, and identity authentication and key negotiation are performed before the connection between the initiator and the receiving party components, thereby achieving the protection effect of network security.
[0083] Embodiment 2
[0084] On the other hand, the present invention also proposes a network interconnection system based on a cluster network. Please refer to Figure 5 , which shows the network interconnection system based on a cluster network in the second embodiment of the present invention. The system includes:
[0085] The first verification module 11 is used to randomly generate a corresponding verification key according to the connection request when obtaining the connection request initiated by the initiator;
[0086] The second verification module 12 is used to perform data verification on the verification key. If the data verification passes, the connection private key of the initiator and the corresponding receiving identifier are extracted from the connection request;
[0087] Further, the second verification module 12 includes:
[0088] The hash verification unit is used to perform hash calculation on the verification key to obtain a corresponding hash attribute value, and verify the hash attribute value. If the hash attribute value verification passes, a data verification passed signal is sent;
[0089] The private key acquisition unit is used to obtain the certificate chain of the initiator from the connection request, and obtain the connection private key of the initiator and the corresponding receiving identifier according to the certificate chain.
[0090] The key generation module 13 is used to determine the receiving party according to the receiving identifier, and generate a corresponding session key by using the connection private key fed back by the receiving party based on the verification key and the connection private key of the initiator;
[0091] Further, the key generation module 13 includes:
[0092] A data feedback unit, configured to find a corresponding recipient among all independent users of the cluster network according to the received identifier, and use a key matrix algorithm to obtain a connection private key fed back by the recipient based on the verification key;
[0093] A key generation unit, configured to generate an interaction data packet according to the connection private key fed back by the recipient based on the verification key and the connection private key of the initiator, and generate a corresponding session key by using the verification result of the interaction data packet.
[0094] A network interconnection module 14, configured to generate a message authentication code based on the session key, verify the message authentication code, and if the message authentication code passes the verification, obtain the session parameters of the connection party based on the session key, generate a corresponding deployment policy according to the session parameters, and use the deployment policy to implement network interconnection between the initiator and the recipient.
[0095] Further, the network interconnection module 14 includes:
[0096] A data parsing unit, configured to parse the response time of the random number of the session key, determine whether the response time of the random number times out, and if the response time of the random number does not time out, save the random number of the session key;
[0097] A handshake authentication unit, configured to generate a corresponding authentication data packet according to the random number of the session key, and authenticate the authentication data packet by using a preset handshake authentication algorithm to obtain a corresponding authentication result.
[0098] In some alternative embodiments, the system further includes:
[0099] An information acquisition module, configured to acquire user information of all independent users in the cluster network, where the user information includes a communication protocol, a sending identifier, and a corresponding received identifier;
[0100] A protocol generation module, configured to randomly generate a corresponding connection key according to the communication protocol of each independent user, and construct a security control protocol corresponding to each independent user based on the connection key and the communication protocol;
[0101] A virtual connection module, configured to define a secure communication protocol between each independent user by using each security control protocol, and construct a virtual connection between each independent user based on the secure communication protocol.
[0102] The functions or operation steps implemented when the above-mentioned modules and units are executed are substantially the same as those in the above method embodiments, and will not be elaborated here.
[0103] The network interconnection system based on a cluster network provided by the embodiments of the present invention has the same implementation principle and technical effects as those of the foregoing method embodiments. For the sake of brief description, for parts not mentioned in the system embodiments, reference may be made to the corresponding content in the foregoing method embodiments.
[0104] Embodiment III
[0105] The present invention also provides a computer. Please refer to Figure 6 , which shows the computer in the third embodiment of the present invention, including a memory 10, a processor 20, and a computer program 30 stored on the memory 10 and executable on the processor 20. When the processor 20 executes the computer program 30, the above-mentioned network interconnection method based on a cluster network is implemented.
[0106] Among them, the memory 10 includes at least one type of storage medium, and the storage medium includes flash memory, hard disk, multimedia card, card-type memory (such as SD or DX memory, etc.), magnetic memory, magnetic disk, optical disc, etc. The memory 10 can be an internal storage unit of the computer in some embodiments, such as the hard disk of the computer. The memory 10 can also be an external storage device in other embodiments, such as a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. Further, the memory 10 can also include both the internal storage unit of the computer and the external storage device. The memory 10 can be used not only to store application software installed on the computer and various types of data, but also to temporarily store data that has been output or will be output.
[0107] Among them, the processor 20 can be an Electronic Control Unit (ECU, also known as a vehicle computer for short), a Central Processing Unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chips in some embodiments, and is used to run the program code stored in the memory 10 or process data, such as executing an access restriction program, etc.
[0108] It should be noted that Figure 6 the structure shown does not constitute a limitation on the computer. In other embodiments, the computer may include fewer or more components than shown in the figure, or combine some components, or have different component arrangements.
[0109] The embodiments of the present invention also provide a storage medium, on which a computer program is stored, and when the program is executed by a processor, the above-mentioned network interconnection method based on a cluster network is implemented.
[0110] Those skilled in the art can understand that the logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatuses, or devices. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by or in combination with an instruction execution system, apparatus, or device.
[0111] More specific examples (non-exhaustive list) of computer-readable media include the following: an electrical connection part (electronic device) having one or more wirings, a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, a computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other suitable processing as necessary, and then stored in a computer memory.
[0112] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits having appropriate combinational logic gate circuits, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0113] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as falling within the scope described in this specification.
[0114] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A network interconnection method based on a cluster network, characterized in that: include: Acquire user information of all independent users in the cluster network, wherein the user information includes a communication protocol, a sending identifier, and a corresponding receiving identifier; Randomly generate a corresponding connection key according to the communication protocol of each independent user, and construct a security control protocol corresponding to each independent user based on the connection key and the communication protocol; Defining a secure communication protocol between the independent users using the security control protocols, and establishing a virtual connection between the independent users based on the secure communication protocol; When a connection request initiated by the initiator is obtained, a corresponding verification key is randomly generated according to the connection request; Performing data verification on the verification key, and if the data verification passes, extracting the connection private key of the initiator and the corresponding receiving identifier from the connection request; Determine the recipient according to the receiving identifier, and generate a corresponding session key using the connection private key fed back by the recipient based on the verification key and the connection private key of the initiator; A message authentication code is generated based on the session key and verified. If the message authentication code is verified successfully, the session parameters of the connecting party are obtained based on the session key, and a corresponding deployment strategy is generated according to the session parameters. The deployment strategy is used to realize network interconnection between the initiator and the receiver.
2. The network interconnection method based on cluster network according to claim 1, characterized in that: The step of performing data verification on the verification key and, if the data verification passes, extracting the connection private key of the initiator and the corresponding receiving identifier in the connection request comprises: Performing hash calculation on the verification key to obtain a corresponding hash attribute value, and verifying the hash attribute value, and sending a data verification pass signal if the hash attribute value passes the verification; The certificate chain of the initiator is obtained from the connection request, and the connection private key and the corresponding receiving identifier of the initiator are obtained according to the certificate chain.
3. The network interconnection method based on cluster network according to claim 2, characterized in that: The steps of determining the receiving party according to the receiving identifier and generating a corresponding session key by using the connection private key fed back by the receiving party based on the verification key and the connection private key of the initiator include: Find the corresponding receiver among all independent users of the cluster network according to the receiving identifier, and obtain the connection private key fed back by the receiver based on the verification key by using a key matrix algorithm; An interactive data packet is generated according to the connection private key fed back by the receiver based on the verification key and the connection private key of the initiator, and a corresponding session key is generated using the verification result of the interactive data packet.
4. The network interconnection method based on cluster network according to claim 2, characterized in that: The steps of generating a message authentication code based on the session key and verifying the message authentication code include: Parsing the response time of the random number of the session key, determining whether the response time of the random number has timed out, and if the response time of the random number has not timed out, saving the random number of the session key; A corresponding authentication data packet is generated according to the random number of the session key, and the authentication data packet is authenticated using a preset handshake authentication algorithm to obtain a corresponding authentication result.
5. A network interconnection system based on a cluster network, characterized in that: include: An information acquisition module, used to acquire user information of all independent users in the cluster network, wherein the user information includes a communication protocol, a sending identifier and a corresponding receiving identifier; A protocol generation module, used to randomly generate a corresponding connection key according to the communication protocol of each independent user, and construct a security control protocol corresponding to each independent user based on the connection key and the communication protocol; A virtual connection module, used to define a secure communication protocol between each of the independent users using each of the security control protocols, and to establish a virtual connection between each of the independent users based on the secure communication protocol; A first verification module, configured to randomly generate a corresponding verification key according to a connection request initiated by an initiator when a connection request initiated by the initiator is obtained; A second verification module is used to perform data verification on the verification key, and if the data verification passes, extract the connection private key of the initiator and the corresponding receiving identifier from the connection request; A key generation module, used to determine the recipient according to the receiving identifier, and generate a corresponding session key using the connection private key fed back by the recipient based on the verification key and the connection private key of the initiator; A network interconnection module is used to generate a message authentication code based on the session key and verify the message authentication code. If the message authentication code is verified, the session parameters of the connecting party are obtained based on the session key, and a corresponding deployment strategy is generated according to the session parameters. The deployment strategy is used to realize network interconnection between the initiator and the receiver.
6. The network interconnection system based on cluster network according to claim 5, characterized in that: The second verification module includes: A hash verification unit, used to perform hash calculation on the verification key to obtain a corresponding hash attribute value, and verify the hash attribute value, and if the hash attribute value is verified successfully, send a data verification successful signal; The private key acquisition unit is used to acquire the certificate chain of the initiator from the connection request, and acquire the connection private key and the corresponding receiving identifier of the initiator according to the certificate chain.
7. A storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the network interconnection method based on a cluster network as described in any one of claims 1 to 4 is implemented.
8. A computer comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the network interconnection method based on the cluster network as described in any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Rapid authentication method for wireless Mesh network backbone node switching
CN101867930A