Secret-related switch port communication processing method and device, secret-related switch and system
By introducing negotiation, authentication and communication modules into confidential switches to detect and authenticate the identity information of confidential network cards, the problem of lack of strict authentication mechanisms for network switches in the prior art is solved, and effective security protection for confidential networks is achieved.
Patent Information
- Application Number
- CN202510450094.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The existing network switches lack a strict and effective authentication mechanism, which leads to non-confidential devices that may access network switches at will and access confidential networks, seriously threatening network security.
By introducing negotiation module, authentication module and communication module into confidential switches, the working mode of the negotiation port when the confidential network card is accessed is detected, a physical connection is established, and the identity information of the network card is obtained and authenticated. Communication is only allowed after the authentication is successful.
It effectively avoids non-confidential devices from accessing confidential switches at will, ensures the network security of confidential networks, and indirectly authenticates the identity information of the target device by authenticating the identity information of the confidential network card on the physical layer.
Smart Images

Figure CN119996077A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method and device for processing confidential switch port communications, a confidential switch, and a system. Background Art
[0002] With the continuous development of network technology, the security of confidential networks has received more and more attention. In order to ensure the security of confidential networks, network switches are usually used to perform security authentication on terminal devices accessing confidential networks. However, existing network switches often lack strict and effective authentication mechanisms for connected terminal devices, which can easily lead to non-confidential devices arbitrarily accessing network switches to access confidential networks, seriously threatening the network security of confidential networks. Summary of the invention
[0003] The purpose of the embodiments of the present application is to provide a confidential switch port communication processing method, device, confidential switch and system, so as to achieve the technical effect of effectively ensuring the network security of the confidential network.
[0004] In a first aspect, an embodiment of the present application provides a method for processing confidential switch port communications, which is applied to a confidential switch; the method includes: When it is detected that a confidential network card is connected to the port of the confidential switch, negotiate the port working mode with the confidential network card to establish a physical connection with the confidential network card; When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; When the identity information authentication of the confidential network card is successful, the confidential network card is used to communicate with the target device where the confidential network card is located according to the negotiated port working mode.
[0005] In the above implementation process, by pre-configuring a confidential network card for the target device, the confidential switch, when detecting that a confidential network card is connected to the port of the confidential switch, negotiates the port working mode with the confidential network card to establish a physical connection with the confidential network card. When the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. When the identity information of the confidential network card is successfully authenticated, the confidential network card is used to communicate with the target device where the confidential network card is located in accordance with the negotiated port working mode. The confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0006] Furthermore, the authentication of the identity information of the confidential network card includes: Get the identity information of multiple authorized network cards; Comparing the identity information of the confidential network card with the identity information of each authorized network card in the plurality of authorized network cards; When the identity information of the confidential network card is consistent with the identity information of any authorized network card among the multiple authorized network cards, determining that the identity information authentication of the confidential network card is successful; When the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, it is determined that the identity information authentication of the confidential network card has failed.
[0007] In the above implementation process, the confidential switch compares the identity information of the confidential network card with the identity information of each authorized network card in multiple authorized network cards. When the identity information of the confidential network card is consistent with the identity information of any authorized network card in the multiple authorized network cards, it is determined that the identity information authentication of the confidential network card is successful; when the identity information of the confidential network card is inconsistent with the identity information of multiple authorized network cards, it is determined that the identity information authentication of the confidential network card has failed. This can effectively improve the authentication efficiency of the confidential switch on the identity information of the confidential network card.
[0008] Furthermore, the identity information of the plurality of authorized network cards includes identity information of at least one network card authorized by the trusted server.
[0009] In the above implementation process, by obtaining the identity information of at least one network card authorized by the trusted server through the confidential switch, a trusted server can be introduced to accurately determine whether to authorize the network card based on the trusted authentication mechanism, thereby ensuring that the confidential switch accurately authenticates the identity information of the confidential network card, which is conducive to further ensuring the network security of the confidential network.
[0010] Further, the communicating with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode includes: When the negotiated port operating mode meets the preset re-negotiation condition, renegotiate the port operating mode with the confidential network card to determine the target port operating mode; According to the target port working mode, communication is performed with the target device through the confidential network card.
[0011] In the above implementation process, when the negotiated port working mode meets the preset re-negotiation conditions, the confidential switch renegotiates the port working mode with the confidential network card to determine the target port working mode, and communicates with the target device through the confidential network card according to the target port working mode. This ensures that the confidential switch communicates with the target device through the confidential network card according to the optimal port working mode supported by the confidential network card, which is beneficial to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0012] Furthermore, the negotiated port operating mode includes a negotiated port rate; and the preset re-negotiation condition includes that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card.
[0013] In the above implementation process, considering that the port working mode usually includes the port rate, by setting the preset re-negotiation conditions including that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card, the confidential switch can quickly and accurately determine whether it is necessary to renegotiate the port working mode with the confidential network card to optimize the negotiated port working mode, and ensure that the confidential switch communicates with the target device through the confidential network card in accordance with the optimal port working mode supported by it and the confidential network card, which is beneficial to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0014] Further, the communicating with the target device through the confidential network card includes: The confidential network card is triggered to open a network port, and communication is performed with the target device through the network port of the confidential network card.
[0015] In the above implementation process, the confidential switch triggers the confidential network card to open the network port, and communicates with the target device where the confidential network card is located through the network port of the confidential network card, thereby ensuring the stability of communication between the confidential switch and the target device where the confidential network card is located.
[0016] Furthermore, the negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
[0017] In the above implementation process, by negotiating the port working mode including port rate and duplex mode between the confidential switch and the confidential network card, the confidential switch can subsequently strictly follow the negotiated port working mode and communicate with the target device where the confidential network card is located through the confidential network card, which is beneficial to further ensure the network security of the confidential network.
[0018] In a second aspect, an embodiment of the present application provides a confidential switch port communication processing device, which is applied to a confidential switch; the device includes: A negotiation module, configured to negotiate a port working mode with the confidential network card when detecting that a confidential network card is connected to a port of the confidential switch, so as to establish a physical connection with the confidential network card; An authentication module, used to obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card when a physical connection is successfully established with the confidential network card; The communication module is used to communicate with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode when the identity information of the confidential network card is successfully authenticated.
[0019] In a third aspect, an embodiment of the present application provides a confidential switch, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method described above is implemented.
[0020] In a fourth aspect, an embodiment of the present application provides a confidential switch port communication processing system, comprising a confidential switch and at least one target device; each target device in the at least one target device is configured with a confidential network card; The confidential network card configured for each target device is used to access the port of the confidential switch; The confidential switch is used for: When it is detected that a confidential network card is connected to the port of the confidential switch, negotiate the port working mode with the confidential network card to establish a physical connection with the confidential network card; When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; When the identity information authentication of the confidential network card is successful, the confidential network card is used to communicate with the target device where the confidential network card is located according to the negotiated port working mode.
[0021] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes instructions, and when the instructions are executed by a computer, the computer implements the method as described above.
[0022] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0024] Figure 1 A flowchart of a confidential switch port communication processing method provided in the first embodiment of the present application; Figure 2 A schematic diagram of the structure of a confidential switch port communication processing device provided in the second embodiment of the present application; Figure 3 A schematic diagram of the structure of a confidential switch provided in the third embodiment of the present application; Figure 4 A schematic diagram of the structure of a confidential switch port communication processing system provided in the fourth embodiment of the present application. DETAILED DESCRIPTION
[0025] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0026] It should be noted that in the description of this application, the terms "first", "second", etc. are only used to distinguish descriptions and cannot be understood as indicating or implying relative importance. At the same time, the step numbers in the text are only for the convenience of explaining the embodiments of this application and do not serve to limit the order in which the steps are executed. The method provided in the embodiments of this application can be executed by relevant terminal devices, and the following description will be given by taking the central processor in the network switching device as the execution subject as an example.
[0027] In related technologies, in order to ensure the security of confidential networks, network switches are usually used to perform security authentication on terminal devices accessing confidential networks. However, existing network switches often lack strict and effective authentication mechanisms for connected terminal devices, which can easily lead to non-confidential devices arbitrarily accessing network switches to access confidential networks, seriously threatening the network security of confidential networks.
[0028] To this end, an embodiment of the present application proposes a method for processing communication on a confidential switch port, by pre-configuring a confidential network card for the target device, and when the confidential switch detects that a confidential network card is connected to the port of the confidential switch, the confidential switch negotiates the port working mode with the confidential network card to establish a physical connection with the confidential network card, and when the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained, and the identity information of the confidential network card is authenticated, and when the identity information of the confidential network card is successfully authenticated, the confidential network card is used to communicate with the target device where the confidential network card is located in accordance with the negotiated port working mode, and the confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0029] Please see Figure 1 , Figure 1 A flowchart of a method for processing confidential switch port communications provided in the first embodiment of the present application. The first embodiment of the present application provides a method for processing confidential switch port communications, which is applied to a confidential switch; the method includes steps S101 to S103: S101, when it is detected that a confidential network card is connected to a port of a confidential switch, negotiating a port working mode with the confidential network card to establish a physical connection with the confidential network card; S102, when a physical connection with the confidential network card is successfully established, obtaining identity information of the confidential network card, and authenticating the identity information of the confidential network card; S103. When the identity information authentication of the confidential network card is successful, communicate with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0030] As an example, according to actual application requirements, a confidential switch is selected for a confidential network.
[0031] When a target device needs to access a confidential network, a confidential network card is configured for the target device in advance, and the confidential network card configured for the target device will be connected to the port of the confidential switch.
[0032] When the confidential switch detects that a confidential network card is connected to a port of the confidential switch, it negotiates the port working mode with the confidential network card to establish a physical connection with the confidential network card.
[0033] In actual applications, the confidential switch can negotiate the port working mode with the confidential network card according to the standard port working mode negotiation process. For example, the confidential switch sends the port working mode supported by the confidential switch to the confidential network card based on the auto-negotiation mechanism in the IEEE 802.3 standard, and the confidential network card sends the port working mode supported by the confidential network card to the confidential switch based on the auto-negotiation mechanism in the IEEE802.3 standard. The confidential switch and the confidential network card negotiate and select a port working mode from all port working modes supported by both parties to obtain the negotiated port working mode.
[0034] The confidential switch determines whether the confidential switch has successfully established a physical connection with the confidential network card. If it is determined that the physical connection with the confidential network card is successfully established, it is considered that from the physical layer, the confidential switch supports communication with the confidential network card. At this time, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. If it is determined that the physical connection with the confidential network card fails, it is considered that from the physical layer, the confidential switch does not support communication with the confidential network card. At this time, the step of determining whether the confidential switch has successfully established a physical connection with the confidential network card can be returned.
[0035] It should be noted that a confidential network card refers to a network interface card (NIC) used to process confidential information, which has a unique identity information, such as the unique identification number of the chip inside the confidential network card.
[0036] In actual applications, the confidential switch can determine whether the confidential switch has successfully established a physical connection with the confidential network card by identifying the port status of the confidential switch. For example, if the confidential switch identifies that the port status of the confidential switch is in an activated state, such as the "UP" state, it is determined that the confidential switch has successfully established a physical connection with the confidential network card. If the confidential switch identifies that the port status of the confidential switch is in an inactivated state, such as the "DOWN" state, it is determined that the confidential switch has failed to establish a physical connection with the confidential network card.
[0037] When the identity information authentication of the confidential network card succeeds, the confidential switch considers that the target device where the confidential network card is located is a confidential device, and allows the confidential switch to communicate with the target device where the confidential network card is located through the confidential network card. When the identity information authentication of the confidential network card fails, the confidential switch considers that the target device where the confidential network card is located is not a confidential device, and refuses to communicate with the target device where the confidential network card is located through the confidential network card.
[0038] Existing network switches mainly use any of the following methods to authenticate the accessed terminal devices. The first method is to obtain the MAC (Media Access Control) address of the accessed terminal device at the data link layer, and determine whether to allow communication with the accessed terminal device based on a pre-stored white list or black list. The second method is to obtain login information such as a user name and password based on the IP address of the accessed terminal device at the network layer, and determine whether to allow communication with the accessed terminal device based on the verification result of the login information. In the process of authenticating the accessed terminal device, the existing network switch still needs to rely on the communication with the accessed terminal device, lacks a strict and effective authentication mechanism, and easily leads to non-confidential devices arbitrarily accessing the network switch to access the confidential network, which seriously threatens the network security of the confidential network. By pre-configuring a confidential network card for the target device, introducing a confidential switch to first establish a physical connection with the connected confidential network card, authenticating the identity information of the confidential network card at the physical layer, and then choosing whether to allow communication with the target device where the confidential network card is located through the confidential network card based on the authentication result, the confidential switch can be used to indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly restricted, and communication with the target device is not supported at the data link layer and network layer above the physical layer, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0039] In the embodiment of the present application, a confidential network card is configured for the target device in advance. When the confidential switch detects that a confidential network card is connected to the port of the confidential switch, it negotiates with the confidential network card on the port working mode to establish a physical connection with the confidential network card. When the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. When the identity information of the confidential network card is authenticated successfully, the confidential network card is used to communicate with the target device where the confidential network card is located in accordance with the negotiated port working mode. The confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, thereby effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0040] In an optional embodiment, the authentication of the identity information of the confidential network card includes: obtaining the identity information of multiple authorized network cards; comparing the identity information of the confidential network card with the identity information of each of the multiple authorized network cards; when the identity information of the confidential network card is consistent with the identity information of any of the multiple authorized network cards, determining that the authentication of the identity information of the confidential network card is successful; when the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, determining that the authentication of the identity information of the confidential network card has failed.
[0041] As an exemplary example, in order to improve the efficiency of the confidential switch in authenticating the identity information of the confidential network card, the identity information of multiple authorized network cards may be pre-stored in the confidential switch.
[0042] After obtaining the identity information of the confidential network card, the confidential switch retrieves the identity information of multiple authorized network cards, and compares the identity information of the confidential network card with the identity information of each of the multiple authorized network cards. If the identity information of the confidential network card is consistent with the identity information of any of the multiple authorized network cards, the confidential network card is considered to be this authorized network card, and the identity information authentication of the confidential network card is determined to be successful. If the identity information of the confidential network card is inconsistent with the identity information of multiple authorized network cards, it is considered that the confidential network card is not authorized, and the identity information authentication of the confidential network card is determined to have failed.
[0043] In the embodiment of the present application, the confidential switch compares the identity information of the confidential network card with the identity information of each authorized network card in multiple authorized network cards. When the identity information of the confidential network card is consistent with the identity information of any authorized network card in the multiple authorized network cards, it is determined that the identity information authentication of the confidential network card is successful; when the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, it is determined that the identity information authentication of the confidential network card has failed. This can effectively improve the efficiency of the confidential switch in authenticating the identity information of the confidential network card.
[0044] In an optional embodiment, the identity information of the plurality of authorized network cards includes the identity information of at least one network card authorized by the trusted server.
[0045] As an exemplary example, according to actual application requirements, a trusted server is selected based on the collected identity information of multiple network cards.
[0046] The trusted server performs trusted authentication on the identity information of each network card among the multiple network cards. If the identity information authentication of the network card succeeds, the network card is authorized and allowed to participate in accessing the confidential network. If the identity information authentication of the network card fails, the network card is not authorized and is denied to participate in accessing the confidential network, thereby determining the identity information of at least one authorized network card and sending the identity information of at least one authorized network card to the confidential switch, so that the confidential switch can receive and store the identity information of at least one network card authorized by the trusted server.
[0047] In an optional implementation of this embodiment, the trusted server can send configuration instructions to the confidential switch based on the RADIUS or EAPOL protocol, triggering the confidential switch to mark the port as a trusted access port, not allowing the port to be used as a source of traffic mirroring, and preventing the leakage of encrypted traffic mirroring.
[0048] The embodiment of the present application can introduce a trusted server by obtaining the identity information of at least one network card authorized by a trusted server through the confidential switch, and accurately determine whether to authorize the network card based on a trusted authentication mechanism, thereby ensuring that the confidential switch accurately authenticates the identity information of the confidential network card, which is beneficial to further ensure the network security of the confidential network.
[0049] In an optional embodiment, the method of communicating with the target device where the confidential network card is located through the confidential network card according to the negotiated port operating mode includes: when the negotiated port operating mode meets the preset re-negotiation conditions, renegotiating the port operating mode with the confidential network card to determine the target port operating mode; communicating with the target device through the confidential network card according to the target port operating mode.
[0050] As an example, in actual application scenarios, the confidential switch, without determining the security of the target device where the confidential network card is located, may negotiate a port working mode with the confidential network card that is not the optimal port mode supported by the confidential switch and the confidential network card. In order to improve the communication efficiency between the confidential switch and the target device where the confidential network card is located, renegotiation conditions can be set in advance for the optimal port mode supported by the confidential switch and the confidential network card.
[0051] The confidential switch determines whether the negotiated port working mode meets the preset re-negotiation conditions. If the negotiated port working mode meets the preset re-negotiation conditions, it is considered that the negotiated port working mode is not the optimal port working mode supported by the confidential switch and the confidential network card. At this time, the port working mode is renegotiated with the confidential network card to determine the target port working mode. According to the target port working mode, communication is performed with the target device through the confidential network card. If the negotiated port working mode does not meet the preset re-negotiation conditions, it is considered that the negotiated port working mode is already the optimal port working mode supported by the confidential switch and the confidential network card. At this time, communication is performed directly with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0052] In the embodiment of the present application, when the negotiated port operating mode meets the preset re-negotiation condition, the confidential switch renegotiates the port operating mode with the confidential network card, determines the target port operating mode, and communicates with the target device through the confidential network card according to the target port operating mode. This ensures that the confidential switch communicates with the target device through the confidential network card according to the optimal port operating mode supported by the confidential network card, which is beneficial to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0053] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate; the preset re-negotiation condition includes that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card.
[0054] As an example, in actual application scenarios, the port working mode usually includes the port rate. Under the premise of not knowing the security of the target device where the confidential network card is located, in order to avoid frequent attacks, the confidential switch may negotiate with the confidential network card the minimum port rate supported by the confidential switch and the confidential network card, rather than the maximum port rate supported by the confidential switch and the confidential network card. In order to improve the communication efficiency between the confidential switch and the target device where the confidential network card is located, renegotiation conditions can be set in advance for the maximum port supported by the confidential switch and the confidential network card, such as the preset renegotiation conditions including the negotiated port rate being less than the maximum port rate supported by the confidential switch and the confidential network card.
[0055] When the identity information of the confidential network card is successfully authenticated, the confidential switch obtains the negotiated port working mode, where the negotiated port working mode includes the negotiated port rate, and determines whether the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card. If the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card, it is determined that the negotiated port working mode meets the preset re-negotiation condition, and it is considered that the negotiated port working mode is not the optimal port working mode supported by the confidential switch and the confidential network card. At this time, the port working mode is renegotiated with the confidential network card to determine the target port working mode. According to the target port working mode, communication is performed with the target device through the confidential network card. If the negotiated port rate is equal to the maximum port rate supported by the confidential switch and the confidential network card, it is determined that the negotiated port working mode does not meet the preset re-negotiation condition, and it is considered that the negotiated port working mode is already the optimal port working mode supported by the confidential switch and the confidential network card. At this time, communication is performed directly with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0056] The embodiments of the present application take into account that the port operating mode usually includes the port rate. By setting a preset re-negotiation condition including that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card, the confidential switch can quickly and accurately determine whether it is necessary to renegotiate the port operating mode with the confidential network card to optimize the negotiated port operating mode, thereby ensuring that the confidential switch communicates with the target device through the confidential network card in accordance with the optimal port operating mode supported by the confidential network card, which is beneficial to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0057] In an optional embodiment, the communicating with the target device through the confidential network card includes: triggering the confidential network card to open a network port, and communicating with the target device through the network port of the confidential network card.
[0058] As an example, when the identity information of the confidential network card is successfully authenticated, the confidential switch considers that the target device where the confidential network card is located is a confidential device, and allows the confidential switch to communicate with the target device where the confidential network card is located through the confidential network card. At this time, the confidential network card is triggered to open a network port, such as a general Ethernet port, and communicates with the target device where the confidential network card is located through the network port of the confidential network card.
[0059] In the embodiment of the present application, the confidential switch triggers the confidential network card to open the network port, and communicates with the target device where the confidential network card is located through the network port of the confidential network card, thereby ensuring the communication stability between the confidential switch and the target device where the confidential network card is located.
[0060] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
[0061] As an exemplary embodiment, when the confidential switch detects that a confidential network card is connected to a port of the confidential switch, it negotiates with the confidential network card on a port working mode including a port rate and a duplex mode to establish a physical connection with the confidential network card.
[0062] In actual applications, the confidential switch can negotiate the port working mode with the confidential network card according to the standard port working mode negotiation process. For example, the confidential switch sends the port rate and duplex mode supported by the confidential switch to the confidential network card based on the auto-negotiation mechanism in the IEEE 802.3 standard, and the confidential network card sends the port rate and duplex mode supported by the confidential network card to the confidential switch based on the auto-negotiation mechanism in the IEEE 802.3 standard. The confidential switch and the confidential network card negotiate to select a port rate from all port rates supported by both parties, and negotiate to select a duplex mode from all duplex modes supported by both parties, thereby determining that the negotiated port working mode includes the negotiated port rate and the negotiated duplex mode.
[0063] In the embodiment of the present application, by having the confidential switch and the confidential network card negotiate the port operating mode including the port rate and the duplex mode, the confidential switch can subsequently strictly follow the negotiated port operating mode and communicate with the target device where the confidential network card is located through the confidential network card, which is beneficial to further ensure the network security of the confidential network.
[0064] Please see Figure 2 , Figure 2 A schematic diagram of the structure of a confidential switch port communication processing device provided for the second embodiment of the present application. The second embodiment of the present application provides a confidential switch port communication processing device, which is applied to a confidential switch; the device includes: a negotiation module 201, which is used to negotiate the port working mode with the confidential network card when it is detected that a confidential network card is connected to the port of the confidential switch, so as to establish a physical connection with the confidential network card; an authentication module 202, which is used to obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card when the physical connection with the confidential network card is successfully established; a communication module 203, which is used to communicate with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode when the identity information of the confidential network card is successfully authenticated.
[0065] In an optional embodiment, the authentication of the identity information of the confidential network card includes: obtaining the identity information of multiple authorized network cards; comparing the identity information of the confidential network card with the identity information of each of the multiple authorized network cards; when the identity information of the confidential network card is consistent with the identity information of any of the multiple authorized network cards, determining that the authentication of the identity information of the confidential network card is successful; when the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, determining that the authentication of the identity information of the confidential network card has failed.
[0066] In an optional embodiment, the identity information of the plurality of authorized network cards includes the identity information of at least one network card authorized by the trusted server.
[0067] In an optional embodiment, the method of communicating with the target device where the confidential network card is located through the confidential network card according to the negotiated port operating mode includes: when the negotiated port operating mode meets the preset re-negotiation conditions, renegotiating the port operating mode with the confidential network card to determine the target port operating mode; communicating with the target device through the confidential network card according to the target port operating mode.
[0068] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate; the preset re-negotiation condition includes that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card.
[0069] In an optional embodiment, the communicating with the target device through the confidential network card includes: triggering the confidential network card to open a network port, and communicating with the target device through the network port of the confidential network card.
[0070] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
[0071] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, which will not be repeated here.
[0072] Please see Figure 3 , Figure 3 The third embodiment of the present application provides a confidential switch 30, comprising a processor 301, a memory 302, and a computer program stored in the memory 302 and configured to be executed by the processor 301; when the processor 301 executes the computer program, the method described in the first embodiment of the present application is implemented, and the same beneficial effects can be achieved.
[0073] When the processor 301 reads the computer program from the memory 302 through the bus 303 and executes the computer program, the method of any embodiment included in the method described in the first embodiment of the present application can be implemented.
[0074] Processor 301 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 301 can be a microprocessor.
[0075] The memory 302 may be used to store instructions executed by the processor 301 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 301 of the disclosed embodiment may be used to execute instructions in the memory 302 to implement the method described in the first embodiment of the present application. The memory 302 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.
[0076] Please see Figure 4 , Figure 4 A structural diagram of a confidential switch port communication processing system provided for the fourth embodiment of the present application. The fourth embodiment of the present application provides a confidential switch port communication processing system, including a confidential switch 401 and at least one target device 402; each target device 402 in the at least one target device 402 is configured with a confidential network card; the confidential network card configured in each target device 402 is used to access the port of the confidential switch 401; the confidential switch 401 is used to: when it is detected that a confidential network card is connected to the port of the confidential switch 401, negotiate the port working mode with the confidential network card to establish a physical connection with the confidential network card; when the physical connection with the confidential network card is successfully established, obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card; when the identity information of the confidential network card is successfully authenticated, communicate with the target device 402 where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0077] The implementation process of the functions and effects of the confidential switch in the above system is specifically described in the implementation process of the corresponding steps in the above method, which will not be repeated here.
[0078] The fifth embodiment of the present application provides a computer program product, which includes instructions. When the instructions are executed by a computer, the computer implements the method described in the first embodiment of the present application and can achieve the same beneficial effects.
[0079] The method described in the first embodiment of the present application can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. A computer program product includes one or more computer programs or instructions. When a computer program or instruction is loaded and executed on a computer, the processes or functions described in each embodiment of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model) or other programmable device.
[0080] A computer program or instruction may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, a computer program or instruction may be transmitted from one website, computer, server or data center to another website, computer, server or data center by wired or wireless means. A computer-readable storage medium may be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. Available media may be magnetic media, such as a floppy disk, hard disk, or magnetic tape; may also be optical media, such as a digital video disk; or may be semiconductor media, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.
[0081] The sixth embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described in the first embodiment of the present application, and can achieve the same beneficial effects as the method described in the first embodiment of the present application.
[0082] In summary, the embodiments of the present application provide a method, device, confidential switch and system for processing port communication of a confidential switch. The method for processing port communication of a confidential switch is applied to a confidential switch; the method comprises: when it is detected that a confidential network card is connected to a port of a confidential switch, negotiating a port working mode with the confidential network card to establish a physical connection with the confidential network card; when the physical connection with the confidential network card is successfully established, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; when the identity information of the confidential network card is successfully authenticated, communicating with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode. In the embodiment of the present application, a confidential network card is configured for the target device in advance. When the confidential switch detects that a confidential network card is connected to the port of the confidential switch, it negotiates with the confidential network card on the port working mode to establish a physical connection with the confidential network card. When the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. When the identity information of the confidential network card is authenticated successfully, the confidential network card is used to communicate with the target device where the confidential network card is located in accordance with the negotiated port working mode. The confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, thereby effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0083] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0084] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0085] If the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program codes.
[0086] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A method for processing confidential switch port communications, characterized in that: Applied to a confidential switch; the method comprises: When it is detected that a confidential network card is connected to the port of the confidential switch, negotiate the port working mode with the confidential network card to establish a physical connection with the confidential network card; When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; When the identity information authentication of the confidential network card is successful, the confidential network card is used to communicate with the target device where the confidential network card is located according to the negotiated port working mode.
2. The method according to claim 1, characterized in that The authenticating the identity information of the confidential network card includes: Get the identity information of multiple authorized network cards; Comparing the identity information of the confidential network card with the identity information of each authorized network card in the plurality of authorized network cards; When the identity information of the confidential network card is consistent with the identity information of any authorized network card among the multiple authorized network cards, determining that the identity information authentication of the confidential network card is successful; When the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, it is determined that the identity information authentication of the confidential network card has failed.
3. The method according to claim 2, characterized in that The identity information of the plurality of authorized network cards includes identity information of at least one network card authorized by a trusted server.
4. The method according to claim 1, characterized in that: The method of communicating with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode includes: When the negotiated port operating mode meets the preset re-negotiation condition, renegotiate the port operating mode with the confidential network card to determine the target port operating mode; According to the target port working mode, communication is performed with the target device through the confidential network card.
5. The method according to claim 4, characterized in that The negotiated port working mode includes a negotiated port rate; the preset re-negotiation condition includes that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card.
6. The method according to claim 1, characterized in that The communicating with the target device through the confidential network card includes: The confidential network card is triggered to open a network port, and communication is performed with the target device through the network port of the confidential network card.
7. The method according to any one of claims 1 to 6, characterized in that: The negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
8. A confidential switch port communication processing device, characterized in that: Applicable to confidential switches; the device comprises: A negotiation module, configured to negotiate a port working mode with the confidential network card when detecting that a confidential network card is connected to a port of the confidential switch, so as to establish a physical connection with the confidential network card; An authentication module, used to obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card when a physical connection is successfully established with the confidential network card; The communication module is used to communicate with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode when the identity information of the confidential network card is successfully authenticated.
9. A confidential switch, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A confidential switch port communication processing system, characterized in that: It includes a confidential switch and at least one target device; each target device in the at least one target device is configured with a confidential network card; The confidential network card configured for each target device is used to access the port of the confidential switch; The confidential switch is used for: When it is detected that a confidential network card is connected to the port of the confidential switch, negotiate the port working mode with the confidential network card to establish a physical connection with the confidential network card; When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; When the identity information authentication of the confidential network card is successful, the confidential network card is used to communicate with the target device where the confidential network card is located according to the negotiated port working mode.
Citation Information
Patent Citations
Network card driving method and device, and storage medium
CN108712290A
Authentication method of trusted computing equipment, equipment and server
CN116707758A
Data access method and network security switch
CN117978510A
Network card automatic binding method and device, equipment, medium and program product
CN119402446A
Physical switch information acquisition method, computing device and physical switch
CN119629015A