Method and related device for authenticating, encrypting, and decrypting data
The method uses XDP and national cryptographic algorithms to securely and efficiently encrypt and authenticate data at the link layer without modifying endpoints, addressing transparency and performance issues in network communication.
Patent Information
- Application Number
- CN202510322616.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-03-19
AI Technical Summary
In data transmission between terminals and service systems, existing link layer security technologies have insufficient transparency, performance problems, strong hardware dependence, and insufficient flexibility and adaptability, resulting in unsafe data transmission.
XDP technology is used to capture data packets at the link layer, and combined with the national secret algorithms SM2, SM3, and SM4, the encryption, signature, authentication and decryption of data packets is realized in the terminal side module and gateway module through multi-threading technology, and the task allocation is used to ensure the security and efficiency of data transmission.
It realizes secure encryption of data transmission between terminals and business systems, improves system performance and transparency, adapts to complex network environments, reduces system overhead, and ensures data integrity and legality.
Smart Images

Figure CN119854038B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and in particular, to a method and related device for authenticating, encrypting, and decrypting data. Background Art
[0002] With the rapid development of network technologies and the continuous improvement of information security requirements, link-layer security technologies have gradually become an important direction in network security research. Especially in network scenarios with high-performance and low-latency requirements, the link-layer transparent authentication and encryption mechanism has received extensive attention due to its high efficiency and transparency.
[0003] In some application scenarios, the data transmission between the terminal and the service system does not encrypt and authenticate the data, which is not conducive to the secure transmission of data. However, directly adding an encryption and authentication mechanism to the terminal and the service system requires modifications to the terminal and the service system, which is rather inconvenient. Summary of the Invention
[0004] In view of this, the purpose of this application is to propose a method and related device for authenticating, encrypting, and decrypting data to solve or partially solve the above problems.
[0005] Based on the above purpose, in the first aspect of this application, a method for authenticating, encrypting, and decrypting data is provided, including:
[0006] Obtain an original data packet, where the original data packet is captured at the link layer using XDP technology;
[0007] Encrypt the payload of the original data packet to obtain a first data packet;
[0008] Generate a message digest and sign the message digest to generate a message authentication code;
[0009] Encapsulate the message authentication code and the first data packet to obtain a second data packet;
[0010] Verify the authenticity of the second data packet;
[0011] In response to the successful verification of the second data packet, write the second data packet into the decryption thread queue for decryption to obtain the original data packet.
[0012] Optionally, the obtaining of the original data packet further includes:
[0013] Perform first-layer filtering, second-layer filtering, and third-layer filtering on multiple target data packets at the kernel layer to obtain the original data packet;
[0014] Among them, the first - layer filtering filters out irrelevant traffic based on the source address, destination address, and port number; the second - layer filtering narrows the target range based on the protocol field; and the third - layer filtering performs specific rule matching on the payload of the original packet.
[0015] Optionally, the generating a message digest and signing the message digest to generate a message authentication code further includes:
[0016] In the signature thread queue, generate the message digest using the SM3 algorithm;
[0017] Generate a public key and a private key using the SM2 algorithm, where the public key and the private key are generated in the terminal - side module and the gateway module respectively;
[0018] Sign the message digest using the private key to generate the message authentication code.
[0019] Optionally, the verifying the authenticity of the second packet further includes:
[0020] Read the second packet from the capture thread queue and extract the message authentication code in the second packet in the verification thread queue;
[0021] Recalculate the message digest using SM3 and verify the authenticity of the message authentication code using the public key.
[0022] Optionally, the writing the second packet into the decryption thread queue for decryption to obtain the original packet further includes:
[0023] Read the second packet from the verification thread queue and decrypt the payload of the second packet using the SM4 algorithm in the decryption thread queue to obtain the original packet.
[0024] Optionally, the encrypting the payload of the original packet to obtain a first packet further includes:
[0025] Read the original packet from the capture thread queue and encrypt the payload of the original packet using the SM4 algorithm in the encryption thread queue to obtain the first packet.
[0026] Optionally, the encapsulating the message authentication code and the first packet to obtain a second packet further includes:
[0027] Read the first packet from the signature thread queue and encapsulate the message authentication code and the first packet to obtain the second packet.
[0028] In a second aspect of the present application, there is provided an apparatus for authenticating, encrypting, and decrypting data, comprising:
[0029] An acquisition module, configured to acquire an original data packet, where the original data packet is captured at the link layer by using XDP technology;
[0030] An encryption module, configured to encrypt the payload of the original data packet to obtain a first data packet;
[0031] A generation module, configured to generate a message digest and sign the message digest to generate a message authentication code;
[0032] An encapsulation module, configured to encapsulate the message authentication code and the first data packet to obtain a second data packet;
[0033] A verification module, configured to verify the authenticity of the second data packet;
[0034] A decryption module, configured to, in response to the second data packet passing the verification, write the second data packet into a decryption thread queue for decryption to obtain the original data packet.
[0035] In a third aspect of the present application, there is provided an electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, the method described in the first aspect is implemented.
[0036] In a fourth aspect of the present application, there is provided a non-transitory computer-readable storage medium storing computer instructions for causing a computer to execute the method described in the first aspect.
[0037] As can be seen from the above, the present application provides a method and related devices for authenticating, encrypting, and decrypting data. The method includes: acquiring an original data packet, where the original data packet is captured at the link layer by using XDP technology; encrypting the payload of the original data packet to obtain a first data packet; generating a message digest and signing the message digest to generate a message authentication code; encapsulating the message authentication code and the first data packet to obtain a second data packet; verifying the authenticity of the second data packet; and in response to the second data packet passing the verification, writing the second data packet into a decryption thread queue for decryption to obtain the original data packet. Through the above method, authentication encryption for data transmission between the terminal and the service system is achieved, making the data transmission between the terminal and the service system more secure. Description of the Drawings
[0038] To more clearly illustrate the technical solutions in the present application or related technologies, the following will briefly introduce the accompanying drawings required for use in the embodiments or related technology descriptions. Obviously, the accompanying drawings in the following description are only embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0039] Figure 1 FIG. shows a schematic diagram of an exemplary network packet processing system 100 according to an embodiment of the present application.
[0040] Figure 2 FIG. shows a schematic diagram of an exemplary system architecture 200 according to an embodiment of the present application.
[0041] Figure 3 FIG. shows a schematic diagram of an exemplary device for authenticating, encrypting, and decrypting data according to an embodiment of the present application.
[0042] Figure 4 FIG. shows a schematic diagram of an exemplary electronic device according to an embodiment of the present application. Detailed Embodiments
[0043] To make the objectives, technical solutions, and advantages of the present application more clearly understood, the following further elaborates on the present application in detail in conjunction with specific embodiments and with reference to the accompanying drawings.
[0044] It should be noted that unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present application should have the ordinary meaning understood by those of ordinary skill in the art to which the present application belongs. The "first", "second", and similar terms used in the embodiments of the present application do not indicate any order, quantity, or importance, but are only used to distinguish different components. The terms such as "including" or "comprising" mean that the elements or objects appearing before the term cover the elements or objects listed after the term and their equivalents, without excluding other elements or objects. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left", "right", etc. are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.
[0045] The authentication mechanism is mainly used to verify the identity of network devices and both parties in communication to ensure the legitimacy of the source of the data packet. Commonly used protocols include 802.1X and digital certificate authentication based on PKI (Public Key Infrastructure). The encryption mechanism encrypts the link layer data to prevent data leakage or tampering. For example, MACsec (Media Access Control Security) ensures communication security through Ethernet frame encryption. The management and control platform uses a centralized network security management system to configure and monitor link layer security policies.
[0046] At present, the link layer authentication and encryption technology can be mainly divided into three directions: protocol-based authentication and encryption, hardware-based high-performance implementation, and software-based flexible solutions. Protocol-based authentication and encryption technologies include 802.1X and MACsec. The former implements link layer security through access control, and the latter ensures communication security through Ethernet frame encryption. Although IPSec (Internet Protocol Security, a security protocol suite used to protect Internet protocol communications) is mainly used at the network layer, it can also be used at the link layer to provide more comprehensive protection. Hardware-based high-performance implementation significantly improves the performance of link layer encryption with the help of devices that support hardware acceleration (such as network cards that support AES-NI (Advanced Encryption Standard New Instructions). Software-based flexible solutions use high-performance packet processing technologies such as XDP (eXpress Data Path) and BPF (Berkeley Packet Filter) to perform transparent authentication and encryption at the link layer to adapt to complex and dynamic network environments.
[0047] In the specific application scenarios of authentication and encryption mechanisms, typical technical examples include access control of authentication devices, link layer encryption data protection, and dynamic packet capture and transparent encryption. For example, the 802.1X protocol verifies the legitimacy of access devices through the RADIUS (Remote Authentication Dial-In User Service) server and is widely used in enterprise networks and Wi-Fi (Wireless Fidelity) hotspot management; MACsec encrypts Ethernet frames with high efficiency and adds integrity check information to data packets for the protection of data centers and corporate intranets; XDP-based real-time packet processing technology can complete authentication and encryption operations within millisecond delays and is suitable for high-performance networks. The comprehensive application of these technologies provides an efficient and flexible solution for link layer security in modern network environments.
[0048] The current link layer authentication and encryption technologies can mainly be divided into three major directions: (1) protocol-based authentication and encryption, (2) high-performance implementation based on hardware, and (3) flexible solutions based on software.
[0049] (1) Protocol-based authentication and encryption technology
[0050] 802.1X is a network access control protocol that verifies the identity of devices through a RADIUS server to ensure that only authorized devices can access the network. When a device connects, it needs to provide credentials (such as username, password, or certificate), and it can access the network only after successful authentication. 802.1X is widely used in enterprise networks and Wi-Fi hotspots to prevent unauthorized devices from accessing and supports dynamic key distribution to enhance security. MACsec (IEEE 802.1AE) is an Ethernet link layer encryption protocol that protects the security and integrity of data transmission by encrypting and authenticating Ethernet frames. It uses encryption algorithms such as AES-GCM (Advanced Encryption Standard - Galois / Counter Mode) to add an integrity check value to each frame to prevent data tampering and replay attacks. MACsec supports hop-by-hop encryption and is suitable for high-security scenarios such as data centers and enterprise intranets. It is often used in combination with 802.1X, where 802.1X is responsible for device authentication and MACsec is responsible for data encryption.
[0051] IPSec is mainly used at the network layer, but it can also provide additional protection at the link layer through tunnel mode. It supports encryption, integrity verification, and identity authentication and is suitable for high-security communications across networks.
[0052] (2) High-performance implementation based on hardware
[0053] The high-performance implementation based on hardware significantly improves the performance of link layer encryption by using devices that support hardware acceleration (such as network cards that support the AES-NI instruction set). These hardware acceleration devices can offload encryption and decryption operations from the CPU (Central Processing Unit) to dedicated hardware for execution, thus greatly reducing the burden on the CPU and improving data processing efficiency.
[0054] Taking a network card that supports AES-NI (Advanced Encryption Standard New Instruction Set) as an example, AES-NI is an instruction set specifically designed to accelerate the AES encryption algorithm and can efficiently execute encryption and decryption operations at the hardware level. By offloading the AES encryption algorithm to a network card that supports AES-NI, the performance of link layer encryption can be significantly improved, especially when dealing with large-scale data traffic, enabling higher throughput and lower latency.
[0055] In addition, some high-end network cards (such as SmartNIC (intelligent network card)) also integrate dedicated encryption engines, which can directly perform complex encryption and authentication operations at the hardware level. These network cards not only support AES, but also can accelerate other encryption algorithms (such as ChaCha20, SHA (Secure Hash Algorithm), etc.), further optimizing the performance of link-layer encryption. Through hardware acceleration, network devices can still maintain high-efficient data processing capabilities in high-load environments, and are suitable for scenarios with extremely high network performance requirements such as data centers, cloud computing, and high-performance computing.
[0056] (3)Software-based Flexible Solutions
[0057] Software-based flexible solutions utilize high-performance packet processing technologies such as XDP (eXpress Data Path) to implement transparent authentication and encryption at the link layer, and can effectively cope with complex and dynamically changing network environments. XDP is a high-performance network data processing framework in the Linux operating system kernel, which allows users to directly process network packets in the kernel space, bypassing the traditional kernel network protocol stack, thus significantly reducing latency and improving processing efficiency.
[0058] The core advantage of XDP lies in its ability to operate on network packets before they enter the kernel network protocol stack, which makes it particularly suitable for transparent authentication and encryption at the link layer. Through XDP, network packets can be immediately processed when they arrive at the network card, such as filtering, encrypting, or authenticating, without having to pass the packets to the kernel's network protocol stack. This processing method not only reduces the packet processing path, but also achieves extremely high performance, meeting the requirements of modern networks for low latency and high throughput.
[0059] In link-layer transparent authentication and encryption, XDP can be used to implement various functions. For example, XDP programs can quickly filter out packets that do not conform to security policies, ensuring that only authenticated devices can access the network. At the same time, XDP can also encrypt network packets before they enter the kernel protocol stack, ensuring the security of data during transmission. In addition, XDP programs can dynamically adjust security policies, enabling or disabling specific filtering rules according to the real-time situation of network traffic, so as to adapt to complex and changing network environments.
[0060] The flexibility of XDP is also reflected in its support for dynamic loading and updating. Users can write custom packet handlers using eBPF (Extended Berkeley Packet Filter) and dynamically load them into the kernel for execution. This flexibility enables XDP-based solutions to adapt to different network requirements and security policies. For example, when an attack is detected, more stringent filtering rules can be automatically enabled, or the performance of encryption algorithms can be optimized when the network load is high.
[0061] Although the above methods and technologies have been widely used in different scenarios, the following problems still exist:
[0062] (1) Insufficient transparency: Many existing methods (such as IPSec, 802.1X) have poor transparency at the link layer and require configuration by users or administrators, which may affect the user experience.
[0063] (2) Performance issues: High-performance encryption and authentication mechanisms (such as AES-256, RSA-2048) usually incur significant computational overhead and may become a bottleneck in high-throughput environments.
[0064] (3) Strong hardware dependence: Solutions like MACsec rely on hardware support and cannot be implemented if the device does not support it. This hardware dependence limits the popularity of the technology.
[0065] (4) Lack of flexibility and adaptability: Many technologies are difficult to adapt flexibly in dynamic network environments (such as multi-point connections, heterogeneous networks).
[0066] To at least solve the above problems, the present application provides a method and related device for authenticating, encrypting, and decrypting data. The method includes: obtaining an original data packet, which is captured at the link layer using XDP technology; encrypting the payload of the original data packet to obtain a first data packet; generating a message digest and signing the message digest to generate a message authentication code; encapsulating the message authentication code and the first data packet to obtain a second data packet; verifying the authenticity of the second data packet; and in response to the second data packet passing the verification, writing the second data packet into a decryption thread queue for decryption to obtain the original data packet. Through the above method, the authentication and encryption of data transmission between the terminal and the service system are achieved, making the data transmission between the terminal and the service system more secure.
[0067] Figure 1 FIG. shows a schematic diagram of an exemplary network packet processing system 100 according to an embodiment of the present application.
[0068] As Figure 1As shown in the figure, an embodiment of the present application designs a secure and efficient network packet processing system 100 based on XDP technology to implement a transparent authentication and encryption mechanism for traffic packets. The network packet processing system 100 adds a terminal-side module 106 and a gateway module 108 between the terminal 102 and the service system 104, and combines the XDP technology at the link layer to implement data authentication, encryption and decryption, while maintaining the transparent effect on the terminal 102, and combines multi-thread technology and national cryptography algorithms to improve the framework performance. The specific solutions include: network packet capture and an encryption authentication protocol based on national cryptography algorithms. Specifically, as Figure 1 shown, the terminal 102 sends the original data packet to the terminal-side module 106. The XDP program captures the data packet at the link layer in the capture thread queue, encrypts it using the SM4 algorithm in the encryption thread queue, generates a message digest using the SM3 algorithm in the signature thread queue, and signs the message digest using the SM2 private key to generate a MAC. The terminal-side module 106 sends the encrypted data packet to the gateway module 108. In the capture thread queue, the XDP program captures the data packet at the link layer. In the verification thread queue, it generates a message digest using the SM3 algorithm and verifies the MAC using the SM2 public key. In the decryption thread queue, it decrypts the data packet using the SM4 algorithm. The gateway module 108 sends the decrypted data packet to the service system 104. In this way, without modifying the terminal and the service system, the encryption, authentication and decryption of the data packet are realized through the added terminal-side module and gateway module. At the same time, in the process of data authentication, encryption and decryption, combined with the characteristics of different national cryptography algorithms, different national cryptography algorithms are respectively applied in the signature, message digest generation, encryption stage and decryption stage, and these stages are respectively executed in independent thread queues, which can improve the efficiency of data authentication, encryption and decryption.
[0069] Figure 2 The figure shows a schematic diagram of an exemplary system architecture 200 according to an embodiment of the present application.
[0070] As Figure 2 shown, the system architecture 200 can be a Linux system architecture for processing network packets. The system architecture 200 can include a user layer, a kernel layer and a hardware layer, and describes the processing flow of data packets from the application program to the network interface card (NIC).
[0071] User layer:
[0072] Application programs: These are programs running in the user space. They interact with the kernel through system calls, initiate network requests or process network packets.
[0073] Kernel layer:
[0074] Network protocol stack: This is the part of the operating system kernel responsible for network communication. It processes the transmission of data packets from the application program to the network interface card.
[0075] XDP Hook: XDP is an application of eBPF (Extended Berkeley Packet Filter), which is used to process packets at the very front end of the kernel network stack. It can process packets before they enter the network protocol stack, such as performing operations like quick discarding, filtering, or modification.
[0076] Driver: This is the part in the operating system kernel that directly interacts with hardware devices (such as network interface cards). It is responsible for transferring packets from the hardware layer to the kernel layer, or from the kernel layer to the hardware layer.
[0077] eBPF Virtual Machine: This is a virtual machine in the kernel used to execute eBPF programs. eBPF programs are special kernel modules that can be dynamically loaded into the kernel for execution without changing the kernel source code. They are commonly used in scenarios such as network packet processing and performance monitoring.
[0078] Hardware Layer:
[0079] NIC Network Interface Card: This is a hardware device in a computer that is responsible for making a physical connection to an external network. It transfers network packets from the physical network to the inside of the computer, or from the inside of the computer to the physical network.
[0080] (1) Network Packet Capture:
[0081] Linux eBPF is a lightweight and powerful virtual machine that provides a set of libraries allowing code to be dynamically injected from user-space applications into various kernel events. At the same time, XDP provides special hooks for eBPF kernel programs to effectively pass, discard / filter, and redirect network packets received at network ports. eBPF / XDP programs can be connected to the network driver at three different points, namely skb (generic), native, and hw (HardwareOffloading). The fastest one, i.e., the hw or offload mode, allows the XDP program to run on the NIC itself. However, for this mode, a SmartNIC is required. In the native mode, the XDP hook is called in the driver before the kernel allocates the socket buffer (driver support is required). In the skb or generic mode, the XDP hook is called after the packet DMA (Direct Memory Access) and socket buffer allocation. Therefore, in this case, the processing performance is significantly lower than other modes. We configure the XDP tool and specifically use xdp-dump (using the native mode) for network packet capture.
[0082] Such asFigure 2 As shown in the figure, the XDP program directly operates on the data packets received by the NIC network interface card. In this way, through the XDP technology, the data packets sent by the terminal are captured at the link layer, and the data packets are directly processed in the kernel space, avoiding copying to the user space. The XDP program is run by a single thread to avoid the competition problem introduced by multi-threaded capture. And through the optimized XDP packet capture strategy, the data packets sent by the terminal are captured according to the priority:
[0083] The first layer of filtering: quickly filter out irrelevant traffic based on the source address (Source IP), destination address (Destination IP), and port number.
[0084] The second layer of filtering: further narrow the target range based on the protocol field (such as the TCP (Transmission Control Protocol) flag bit).
[0085] The third layer of filtering: optionally perform specific rule matching (such as regular matching) on the data packet payload.
[0086] Precise filtering based on eBPF:
[0087] XDP relies on the eBPF program to implement the data packet processing logic, and precise data packet capture can be achieved by writing optimized eBPF filtering rules.
[0088] Hierarchical filtering:
[0089] Implement multi-layer filtering logic in the XDP program, and gradually narrow the range of target data packets according to the priority. Hierarchical filtering gradually narrows the target range of the data packets, first processes simple rules, and then gradually deepens complex inspections. This can ensure the accuracy of the data packets while reducing the processing delay.
[0090] (1) The first layer of filtering: Check the data packet header information, aiming to quickly screen out data packets irrelevant to the service and reduce the system burden. The inspection content includes:
[0091] Source address and destination address: Determine whether it belongs to the target IP range, such as using subnet matching.
[0092] Source port and destination port: Screen specific protocols according to the port number (such as port 80 for HTTP and port 443 for HTTPS).
[0093] Message Authentication Code (MAC) address matching: Check the source MAC address of the data packet and discard data packets with illegal or untrusted MAC addresses.
[0094] Packet type: Check the Ethernet frame type field to determine whether it is an IPv4 (Internet Protocol Version 4), IPv6 (Internet Protocol Version 6), or ARP (Address Resolution Protocol) packet.
[0095] (2) Layer 2 filtering: Protocol field check, further filter packets based on the protocol field to precisely match specific service requirements. After passing the first layer of filtering, parse the deeper protocol headers (such as TCP (Transmission Control Protocol) or UDP (User Datagram Protocol)), and use exact comparison (such as port numbers) or partial matching (such as domain names in HTTP fields) to achieve this. The detection content includes:
[0096] TCP flag check: Check whether the packet has specific flags such as SYN (Synchronize Sequence Numbers) or ACK (Acknowledgment) (for example, SYN packets are used to establish connections).
[0097] UDP field check: Verify specific fields of UDP protocols such as DNS (Domain Name System) or DHCP (Dynamic Host Configuration Protocol).
[0098] Application layer protocol field check: Further filter according to HTTP (HyperText Transfer Protocol) header fields or TLS (Transport Layer Security) handshake fields. For example, check whether the HTTP Host field contains the target domain name.
[0099] (3) Layer 3 filtering: Payload data check, parse the payload from the TCP or UDP header and further filter according to regular expressions or predefined rules, and perform more refined analysis on the packet payloads that meet the conditions, such as matching specific keywords. The check content includes:
[0100] Regular expression matching: Match specific strings or formats in the payload (such as the URL of an HTTP request).
[0101] Specific rule matching: Such as detecting whether a specific domain name is included in a DNS query.
[0102] Hash matching filter:
[0103] Hash common traffic characteristics (such as hot IP addresses, port numbers), and use a hash table to quickly find matching rules, reducing the performance overhead caused by complex filtering logic. Establish a flow table cache (flow table), and directly mark the traffic that passes the match to avoid repeated filtering.
[0104] Use an eBPF hash table (BPF_MAP_TYPE_HASH) to cache hot traffic characteristics. When a data packet arrives, first query the hash table, and if there is a match, quickly release or process it.
[0105] (2) Encryption authentication protocol based on national cryptographic algorithms:
[0106] To ensure the authenticity and credibility of the identities of the terminal and the gateway, prevent spoofing attacks, protect sensitive data during the authentication process, and prevent man-in-the-middle attacks, in some embodiments, national cryptographic standard algorithms (SM2, SM3, SM4) can be used in combination with multi-threading technology to implement a more secure and efficient protocol. This protocol can be used for identity authentication between the terminal-side module and the gateway module to ensure the legality of communication and the integrity of data. The protocol includes an initialization phase, an authentication phase, and a key negotiation phase, and establishes secure communication after ensuring the credibility of both parties' identities. Use a high-performance lock-free queue - a producer-consumer queue implemented based on a circular buffer. Tasks such as encryption, signature, decryption, and verification are processed by independent thread pools respectively, and the size of the thread pool can be dynamically adjusted according to system resources and traffic load. Among them, the SM2 algorithm is used to generate public-private key pairs, perform digital signatures and verifications, the SM3 algorithm is used to generate message digests to ensure data integrity, and the SM4 algorithm is used for symmetric encryption to protect the confidentiality of authentication data.
[0107] Encryption authentication protocol based on national cryptographic algorithms:
[0108] The protocol includes an initialization phase, an authentication phase, and a key negotiation phase, and establishes secure communication after ensuring the credibility of both parties' identities.
[0109] It is implemented by combining multi-threading technology with national cryptographic algorithms and using a high-performance lock-free queue - a producer-consumer queue implemented based on a circular buffer. Tasks such as encryption, signature, decryption, and verification are processed by independent thread pools respectively, and the size of the thread pool can be dynamically adjusted according to system resources and traffic load.
[0110] Initialization phase:
[0111] (1) Generation of key pairs for the terminal-side module and the gateway: The terminal and the gateway each generate a pair of SM2 public-private keys. Terminal: (PK T , SK T ), Gateway: (PK G , SK G ), where PK Tand PK G represent the public keys of the terminal and the gateway respectively, and SK T and SK G represent the private keys of the terminal and the gateway respectively.
[0112] (2) Public key exchange and distribution: The terminal-side module and the gateway exchange public keys through a secure channel (pre-deployment, CA (Certificate Authority) signature).
[0113] Authentication phase:
[0114] (1) The terminal-side module sends an authentication request:
[0115] The terminal-side module generates a random number R T .
[0116] Construct an authentication message: , where T is the terminal identifier.
[0117] Use the private key SK T of the terminal-side module to sign the authentication message M T to generate a digital signature:
[0118] .
[0119] Send (M T , S T ) to the gateway. Among them, SM2_Sign represents the algorithm for generating a digital signature by SM2.
[0120] (2) The gateway verifies the identity of the terminal:
[0121] After receiving the message, the gateway extracts M T and S T .
[0122] Use the public key PK T of the terminal-side module to verify the signature: .
[0123] If the verification fails, the authentication request is rejected.
[0124] If the verification is successful, generate a random number R G , and construct an authentication message: , where G is the gateway identifier.
[0125] Use the private key SK G of the gateway to sign the authentication message M G to generate a digital signature: .
[0126] Send (M G , SG ), and send it to the terminal-side module.
[0127] (3) The terminal verifies the gateway's identity:
[0128] After receiving the message, the terminal extracts M G and S G .
[0129] Use the gateway's public key PK G to verify the signature: .
[0130] If the verification fails, terminate the authentication.
[0131] Key negotiation phase:
[0132] (1) Key generation:
[0133] Both parties generate a shared symmetric key K based on the random numbers R T and R G , as well as their respective private and public keys, through the key negotiation algorithm SM2_KeyExchange:
[0134]
[0135] where SM2_KeyExchange represents the key negotiation algorithm.
[0136] (2) Key confirmation:
[0137] Both parties verify the key consistency through the hash check code (SM3):
[0138]
[0139] The terminal sends HMAC T to the gateway, and the gateway calculates the local HMAC and verifies whether they are consistent. HMAC is the hash check value, generated using the SM3 algorithm, and combined with an identifier (such as the string "CONFIRM") as a confirmation signal to verify the consistency of the shared key generated by both parties. Here, "CONFIRM" is a string constant representing the confirmation message, ensuring the uniqueness of key confirmation and preventing replay attacks.
[0140] (3) Subsequent confirmation:
[0141] After successful authentication, both parties use the shared symmetric key K and SM4 encryption for secure communication.
[0142] Multithreaded queue:
[0143] The data packet processing adopts the producer - consumer mode, and the data in each stage is managed by a multi - thread queue to ensure the sequential transfer of tasks. The thread that captures the data packet puts the data into the queue, and after processing, it is handed over to the thread in the next stage.
[0144] Encryption thread pool: Read data packets from the capture thread queue, encrypt the payload of the data packet using the SM4 algorithm, and put the encrypted data packet (e.g., the first data packet) into the signature thread queue.
[0145] Signature thread pool: Generate a message digest using the SM3 algorithm to ensure data integrity. Generate a public - key / private - key pair using the SM2 algorithm, and sign the message digest using the private key to generate a message authentication code (MAC). This step ensures the authenticity and source credibility of the data. Package the encrypted data packet together with the MAC to obtain the second data packet, and directly send the second data packet to the gateway at the link layer through the XDP program.
[0146] Verification thread pool: In the gateway module, read the data packet from the capture thread queue, extract the message authentication code (MAC) and the encrypted payload in the data packet. Recalculate the message digest using SM3, and verify the authenticity of the MAC using the SM2 public key of the terminal to ensure that the data packet has not been tampered with. After passing the verification, write the data packet into the decryption thread queue.
[0147] Decryption thread pool: Read the data packet from the verification thread queue, decrypt the payload using the SM4 algorithm, and put the decrypted data packet into the send queue.
[0148] In the embodiment of this application, by using the XDP technology and taking advantage of its characteristic that it can process data packets before they enter the kernel protocol stack, a secure and efficient network data packet processing framework is designed by adding a terminal module and a gateway module between the terminal and the business system, realizing a transparent authentication and encryption mechanism for data. The deployment of the terminal module and the gateway is transparent to the terminal and the business system, and the terminal and the business system do not need to modify any configuration or code. The terminal module and the gateway retain the original header information of the data packet during the encryption and decryption processes to ensure that the communication between the terminal and the business system is not affected.
[0149] The method provided by the embodiment of this application can achieve the following technical effects:
[0150] (1) Security
[0151] In the traffic road network, considering a large number of terminal devices in the Internet of Things environment, the communication between these terminal devices and the business system is often not secure. Therefore, the embodiments of this application incorporate national cryptographic algorithms (SM2, SM3, SM4) into the XDP network data packet processing framework, and encrypt, sign, authenticate, and decrypt the data packets through the design of a secure and efficient protocol.
[0152] (2)System performance
[0153] By combining multi-threading technology and using a high-performance lock-free queue, tasks such as encryption, signature, decryption, and verification are processed by independent thread pools respectively. The size of the thread pool can be dynamically adjusted according to system resources and traffic load, which can significantly improve throughput and efficiency.
[0154] (3)Transparent authentication
[0155] Utilizing XDP technology, authentication and encryption operations are embedded in the link layer, achieving transparent processing while improving performance. By adding a terminal module and a gateway module between the terminal and the business system, data authentication, encryption, and decryption are realized in the link layer by combining with XDP technology, while maintaining the transparent effect on the terminal and the business system, that is, no modification is required for the terminal and the business system.
[0156] (4)Flexible packet capture and authentication strategy
[0157] Dynamically adjust the packet capture strategy, selectively authenticate and encrypt according to traffic characteristics, and reduce system overhead.
[0158] (5)Security
[0159] This solution is based on national cryptographic algorithms and proposes an encryption and authentication protocol for modules, which can fully guarantee the security of communication.
[0160] (6)Efficiency
[0161] This solution effectively utilizes system resources by combining multi-threading technology. Especially in the scenario of high-concurrency network traffic, parallel processing of tasks is realized, thus significantly improving throughput and efficiency.
[0162] (7)Design based on the XDP network data packet traffic processing framework
[0163] By adding a terminal module and a gateway module between the terminal and the business system, data authentication, encryption, and decryption are realized in the link layer by combining with XDP technology, while maintaining the transparent effect on the terminal and the business system, that is, no modification is required for the terminal and the business system.
[0164] (8)Encryption and authentication mechanism and protocol integrating multi-threading and national cryptographic algorithms
[0165] In the data packet encryption and authentication phase, aiming at problems such as low security and low processing efficiency, an encryption and authentication mechanism and protocol integrating multi-threading and national cryptography algorithms are proposed. This solution can effectively utilize resources, especially in scenarios with high-concurrency network traffic, to achieve parallel processing of tasks, thereby significantly improving throughput and efficiency. And it combines SM2 / SM3 / SM4 algorithms to achieve efficient and secure encryption and authentication.
[0166] It should be noted that the method of the embodiment of the present application can be executed by a single device, such as a computer or a server. The method of this embodiment can also be applied to a distributed scenario and be completed by multiple devices cooperating with each other. In such a distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiment of the present application, and these multiple devices will interact with each other to complete the described method.
[0167] It should be noted that some embodiments of the present application have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order from that in the above embodiments and still achieve the desired results. Additionally, the processes depicted in the drawings do not necessarily require the specific order or sequential order shown to achieve the desired results. In certain embodiments, multi-tasking and parallel processing are also possible or may be advantageous.
[0168] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application also provides a device for authenticating, encrypting, and decrypting data.
[0169] Refer to Figure 3 , the device for authenticating, encrypting, and decrypting data includes:
[0170] An acquisition module 301, configured to acquire an original data packet, where the original data packet is captured at the link layer by using XDP technology.
[0171] The acquisition module 301 is further configured to perform a first-layer filtering, a second-layer filtering, and a third-layer filtering on multiple target data packets in the kernel layer to obtain the original data packet; wherein, the first-layer filtering filters out irrelevant traffic based on the source address, the target address, and the port number, the second-layer filtering narrows the target range based on the protocol field, and the third-layer filtering performs specific rule matching on the payload of the original data packet.
[0172] An encryption module 302, configured to encrypt the payload of the original data packet to obtain a first data packet.
[0173] The encryption module 302 is further configured to read the original data packet from the capture thread queue and encrypt the payload of the original data packet in the encryption thread queue using the SM4 algorithm to obtain the first data packet.
[0174] The generation module 303 is configured to generate a message digest and sign the message digest to generate a message authentication code.
[0175] The generation module 303 is further configured to, in the signature thread queue, generate the message digest using the SM3 algorithm; generate a public key and a private key using the SM2 algorithm, where the public key and the private key are generated in the terminal-side module and the gateway module respectively; sign the message digest using the private key to generate the message authentication code.
[0176] The encapsulation module 304 is configured to encapsulate the message authentication code and the first data packet to obtain a second data packet.
[0177] The encapsulation module 304 is further configured to read the first data packet from the signature thread queue and encapsulate the message authentication code and the first data packet to obtain the second data packet.
[0178] The verification module 305 is configured to verify the authenticity of the second data packet.
[0179] The verification module 305 is further configured to read the second data packet from the capture thread queue, and extract the message authentication code in the second data packet in the verification thread queue; recalculate the message digest using SM3, and verify the authenticity of the message authentication code using the public key.
[0180] The decryption module 306 is configured to, in response to the successful verification of the second data packet, write the second data packet into the decryption thread queue for decryption to obtain the original data packet.
[0181] The decryption module 306 is further configured to read the second data packet from the verification thread queue and decrypt the payload of the second data packet in the decryption thread queue using the SM4 algorithm to obtain the original data packet.
[0182] For the convenience of description, when describing the above device, it is divided into various modules according to functions for separate description. Of course, when implementing the present application, the functions of each module can be implemented in one or more software and / or hardware.
[0183] The device in the above embodiment is used to implement the corresponding method for authenticating, encrypting, and decrypting data in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0184] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the method for authenticating, encrypting, and decrypting data as described in any one of the above embodiments.
[0185] Figure 4 FIG. shows a schematic diagram of an exemplary electronic device according to an embodiment of the present application. The electronic device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. Among them, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are communicatively connected to each other inside the device through the bus 1050.
[0186] The processor 1010 may be implemented in a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present specification.
[0187] The memory 1020 may be implemented in the form of a ROM (Read Only Memory), a RAM (Random Access Memory), a static storage device, a dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When implementing the technical solutions provided in the embodiments of the present specification through software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.
[0188] The input / output interface 1030 is used to connect to an input / output module to implement information input and output. The input / output module may be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.
[0189] The communication interface 1040 is used to connect to a communication module (not shown in the figure) to implement communication interaction between this device and other devices. Among them, the communication module may communicate through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.).
[0190] The bus 1050 includes a path for transmitting information among various components of the device, such as the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040.
[0191] It should be noted that although only the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040, and the bus 1050 are shown in the above device, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the embodiments of this specification, and does not necessarily include all the components shown in the figure.
[0192] The electronic device in the above embodiment is used to implement the corresponding method for authenticating, encrypting, and decrypting data in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0193] Based on the same technical concept, corresponding to the method in any of the above embodiments, the present application also provides a non-transitory computer-readable storage medium. The non-transitory computer-readable storage medium stores computer instructions for causing the computer to execute the method for authenticating, encrypting, and decrypting data as described in any of the foregoing embodiments.
[0194] The computer-readable medium of this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information may be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0195] The computer instructions stored in the storage medium of the above embodiment are used to cause the computer to execute the method for authenticating, encrypting, and decrypting data as described in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated here.
[0196] Those of ordinary skill in the art should understand that any discussion of the above embodiments is merely exemplary and is not intended to imply that the scope of the present application (including the claims) is limited to these examples; under the concept of the present application, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present application as described above, and for the sake of brevity, they are not provided in detail.
[0197] In addition, for simplicity of explanation and discussion, and in order not to make the embodiments of the present application difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present application are to be implemented (i.e., these details should be fully within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present application, it will be apparent to those skilled in the art that the embodiments of the present application may be implemented without these specific details or with variations of these specific details. Accordingly, these descriptions should be regarded as illustrative rather than restrictive.
[0198] Although the present application has been described in connection with specific embodiments of the present application, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0199] The embodiments of the present application are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of the embodiments of the present application shall be included within the protection scope of the present application.
Claims
1. A method for authenticating, encrypting, and decrypting data, characterized in that, including: The terminal-side module obtains an original data packet, which is captured at the link layer by using the XDP technology; encrypt the payload of the original data packet to obtain a first data packet; generate a message digest and sign the message digest to generate a message authentication code; encapsulate the message authentication code and the first data packet to obtain a second data packet; The gateway module verifies the authenticity of the second data packet; In response to the successful verification of the second data packet, the gateway module writes the second data packet into a decryption thread queue for decryption to obtain the original data packet; The gateway module sends the original data packet to the service system; The generating a message digest and signing the message digest to generate a message authentication code further includes: in the signature thread queue, generate the message digest by using the SM3 algorithm; generate a public key and a private key by using the SM2 algorithm, and the public key and the private key are generated in the terminal-side module and the gateway module respectively; sign the message digest by using the private key to generate the message authentication code; verify the authenticity of the second data packet.
2. The method according to claim 1, characterized in that, The obtaining the original data packet further includes: perform first-layer filtering, second-layer filtering, and third-layer filtering on multiple target data packets at the kernel layer to obtain the original data packet; wherein, the first-layer filtering filters out irrelevant traffic based on the source address, target address, and port number, the second-layer filtering narrows the target range based on the protocol field, and the third-layer filtering performs specific rule matching on the payload of the original data packet.
3. The method according to claim 1, wherein The verifying the authenticity of the second data packet further includes: read the second data packet from the capture thread queue and extract the message authentication code in the second data packet in the verification thread queue; recalculate the message digest by using SM3 and verify the authenticity of the message authentication code by using the public key.
4. The method according to claim 1, wherein The writing the second data packet into a decryption thread queue for decryption to obtain the original data packet further includes: read the second data packet from the verification thread queue and decrypt the payload of the second data packet by using the SM4 algorithm in the decryption thread queue to obtain the original data packet.
5. The method according to claim 1, wherein The encrypting the payload of the original data packet to obtain a first data packet further includes: read the original data packet from the capture thread queue and encrypt the payload of the original data packet by using the SM4 algorithm in the encryption thread queue to obtain the first data packet.
6. The method according to claim 1, wherein The encapsulating the message authentication code and the first data packet to obtain a second data packet further includes: read the first data packet from the signature thread queue and encapsulate the message authentication code and the first data packet to obtain the second data packet.
7. An apparatus for authenticating, encrypting, and decrypting data, characterized in that, including: an obtaining module, configured to obtain an original data packet, which is captured at the link layer by using the XDP technology; an encrypting module, configured to encrypt the payload of the original data packet by the terminal-side module to obtain a first data packet; A generation module, configured to generate a message digest and sign the message digest to generate a message authentication code; An encapsulation module, configured to encapsulate the message authentication code and the first data packet to obtain a second data packet; A verification module, configured to verify the authenticity of the second data packet by a gateway module; A decryption module, configured to, in response to the second data packet passing the verification, the gateway module write the second data packet into a decryption thread queue for decryption to obtain the original data packet; A sending module, configured to the gateway module send the original data packet to a service system; The generation module is specifically configured to: In a signature thread queue, generate the message digest by using the SM3 algorithm; Generate a public key and a private key by using the SM2 algorithm, the public key and the private key are respectively generated in the terminal-side module and the gateway module; Sign the message digest by using the private key to generate the message authentication code; Verify the authenticity of the second data packet.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Data security transmission method and system based on autonomous security interaction protocol
CN118784337A
Data stream low-delay encryption transmission system, method and device, storage medium and program product
CN119603083A