Confidential switch port communication processing method, device, confidential switch and system
By configuring confidential network cards and authenticating their identity in confidential switches, the problem of lack of strict authentication of existing network switches is solved, and the security and communication efficiency of confidential networks are improved.
Patent Information
- Application Number
- CN202510450094.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-08-08
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The existing network switches lack a strict and effective authentication mechanism, which makes non-confidential devices prone to access confidential networks at will, threatening network security.
By configuring a confidential network card in a confidential switch, first negotiate the port working mode with it and establish a physical connection, obtain and authenticate the network card identity information, and only allow communication with the target device after the authentication is successful, and the identity of the target device is indirectly authenticated using the physical layer authentication.
Effectively avoid non-confidential devices from accessing confidential networks, ensure network security, improve identity authentication efficiency, and optimize communication efficiency and stability.
Smart Images

Figure CN119996077B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and more specifically, to a method and device for processing confidential switch port communications, a confidential switch, and a system. Background Art
[0002] With the continuous development of network technology, the security of confidential networks is receiving increasing attention. To ensure the security of confidential networks, network switches are often used to authenticate terminal devices accessing confidential networks. However, existing network switches often lack strict and effective authentication mechanisms for connected terminal devices, which can easily lead to non-confidential devices arbitrarily connecting to network switches to access confidential networks, seriously threatening the network security of confidential networks. Summary of the Invention
[0003] The purpose of the embodiments of the present application is to provide a confidential switch port communication processing method, device, confidential switch and system, so as to achieve the technical effect of effectively ensuring the network security of the confidential network.
[0004] In a first aspect, an embodiment of the present application provides a method for processing confidential switch port communications, which is applied to a confidential switch; the method includes:
[0005] When detecting that a confidential network card is connected to a port of the confidential switch, negotiating a port working mode with the confidential network card to establish a physical connection with the confidential network card;
[0006] When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card;
[0007] When the identity information authentication of the confidential network card is successful, communication is performed with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0008] In the above implementation process, by pre-configuring a confidential network card for the target device, the confidential switch negotiates the port working mode with the confidential network card when it detects that a confidential network card is connected to the port of the confidential switch, so as to establish a physical connection with the confidential network card. When the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. When the identity information authentication of the confidential network card is successful, communication is carried out with the target device where the confidential network card is located through the confidential network card in accordance with the negotiated port working mode. The confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0009] Furthermore, the authentication of the identity information of the confidential network card includes:
[0010] Obtain the identity information of multiple authorized network cards;
[0011] Comparing the identity information of the confidential network card with the identity information of each authorized network card in the plurality of authorized network cards;
[0012] When the identity information of the confidential network card is consistent with the identity information of any authorized network card among the multiple authorized network cards, determining that the identity information authentication of the confidential network card is successful;
[0013] When the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, it is determined that the identity information authentication of the confidential network card has failed.
[0014] In the above implementation process, the confidential switch compares the identity information of the confidential network card with the identity information of each authorized network card in multiple authorized network cards. When the identity information of the confidential network card is consistent with the identity information of any authorized network card in multiple authorized network cards, it is determined that the identity information authentication of the confidential network card is successful. When the identity information of the confidential network card is inconsistent with the identity information of multiple authorized network cards, it is determined that the identity information authentication of the confidential network card fails. This can effectively improve the authentication efficiency of the confidential switch on the identity information of the confidential network card.
[0015] Furthermore, the identity information of the plurality of authorized network cards includes identity information of at least one network card authorized by the trusted server.
[0016] In the above implementation process, by obtaining the identity information of at least one network card authorized by the trusted server through the confidential switch, a trusted server can be introduced to accurately determine whether to authorize the network card based on the trusted authentication mechanism, thereby ensuring that the confidential switch accurately authenticates the identity information of the confidential network card, which is conducive to further ensuring the network security of the confidential network.
[0017] Furthermore, the communicating with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode includes:
[0018] When the negotiated port operating mode meets the preset re-negotiation condition, renegotiate the port operating mode with the confidential network card to determine the target port operating mode;
[0019] According to the target port working mode, communication is performed with the target device through the confidential network card.
[0020] In the above implementation process, when the negotiated port working mode meets the preset re-negotiation conditions, the confidential switch renegotiates the port working mode with the confidential network card, determines the target port working mode, and communicates with the target device through the confidential network card according to the target port working mode. This can ensure that the confidential switch communicates with the target device through the confidential network card according to the optimal port working mode supported by it and the confidential network card, which is conducive to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0021] Furthermore, the negotiated port operating mode includes a negotiated port rate; and the preset re-negotiation condition includes that the negotiated port rate is less than a maximum port rate supported by the confidential switch and the confidential network card.
[0022] In the above implementation process, considering that the port working mode usually includes the port rate, by setting the preset re-negotiation conditions including that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card, the confidential switch can quickly and accurately determine whether it is necessary to renegotiate the port working mode with the confidential network card to optimize the negotiated port working mode, and ensure that the confidential switch communicates with the target device through the confidential network card in accordance with the optimal port working mode supported by it and the confidential network card, which is conducive to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0023] Furthermore, the communicating with the target device through the confidential network card includes:
[0024] Trigger the confidential network card to open the network port, and communicate with the target device through the network port of the confidential network card.
[0025] In the above implementation process, the confidential switch triggers the confidential network card to open the network port, and communicates with the target device where the confidential network card is located through the network port of the confidential network card, thereby ensuring the stability of communication between the confidential switch and the target device where the confidential network card is located.
[0026] Furthermore, the negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
[0027] In the above implementation process, the confidential switch and the confidential network card negotiate the port working mode including port rate and duplex mode, so that the confidential switch can subsequently strictly follow the negotiated port working mode and communicate with the target device where the confidential network card is located through the confidential network card, which is conducive to further ensuring the network security of the confidential network.
[0028] In a second aspect, an embodiment of the present application provides a confidential switch port communication processing device, which is applied to a confidential switch; the device includes:
[0029] a negotiation module configured to, upon detecting that a confidential network card is connected to a port of the confidential switch, negotiate a port operating mode with the confidential network card to establish a physical connection with the confidential network card;
[0030] an authentication module, configured to obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card when a physical connection is successfully established with the confidential network card;
[0031] The communication module is used to communicate with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode when the identity information of the confidential network card is successfully authenticated.
[0032] In a third aspect, an embodiment of the present application provides a confidential switch, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method described above is implemented.
[0033] In a fourth aspect, an embodiment of the present application provides a confidential switch port communication processing system, comprising a confidential switch and at least one target device; each target device in the at least one target device is configured with a confidential network card;
[0034] The confidential network card configured for each target device is used to access the port of the confidential switch;
[0035] The confidential switch is used to:
[0036] When detecting that a confidential network card is connected to a port of the confidential switch, negotiating a port working mode with the confidential network card to establish a physical connection with the confidential network card;
[0037] When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card;
[0038] When the identity information authentication of the confidential network card is successful, communication is performed with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0039] In a fifth aspect, an embodiment of the present application provides a computer program product, which includes instructions. When the instructions are executed by a computer, the computer implements the method as described above.
[0040] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.
[0042] Figure 1 A flowchart of a method for processing confidential switch port communications provided in the first embodiment of the present application;
[0043] Figure 2 A schematic diagram of the structure of a confidential switch port communication processing device provided in the second embodiment of the present application;
[0044] Figure 3 A schematic diagram of the structure of a confidential switch provided in the third embodiment of the present application;
[0045] Figure 4 This is a structural diagram of a confidential switch port communication processing system provided in the fourth embodiment of the present application. DETAILED DESCRIPTION
[0046] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0047] It should be noted that in the description of this application, the terms "first" and "second" are used only to distinguish descriptions and should not be understood to indicate or imply relative importance. Furthermore, the step numbers herein are used only to facilitate the explanation of the embodiments of this application and do not serve to define the order in which the steps are executed. The methods provided in the embodiments of this application can be executed by relevant terminal devices, and the following description will be based on the central processing unit within a network switching device as the execution subject.
[0048] In related technologies, in order to ensure the security of confidential networks, network switches are usually used to perform security authentication on terminal devices accessing confidential networks. However, existing network switches often lack a strict and effective authentication mechanism for connected terminal devices, which can easily lead to non-confidential devices arbitrarily connecting to network switches to access confidential networks, seriously threatening the network security of confidential networks.
[0049] To this end, an embodiment of the present application proposes a method for processing communication on a confidential switch port, by pre-configuring a confidential network card for the target device, and when the confidential switch detects that a confidential network card is connected to the port of the confidential switch, the confidential switch negotiates the port working mode with the confidential network card to establish a physical connection with the confidential network card. When the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. When the identity information of the confidential network card is successfully authenticated, communication is carried out with the target device where the confidential network card is located through the confidential network card in accordance with the negotiated port working mode. The confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0050] Please see Figure 1 , Figure 1 This is a flowchart of a method for processing confidential switch port communications provided in the first embodiment of the present application. The first embodiment of the present application provides a method for processing confidential switch port communications, which is applied to a confidential switch; the method includes steps S101 to S103:
[0051] S101. When detecting that a confidential network card is connected to a port of a confidential switch, negotiate a port working mode with the confidential network card to establish a physical connection with the confidential network card;
[0052] S102. When a physical connection is successfully established with the confidential network card, obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card;
[0053] S103: When the identity information authentication of the confidential network card is successful, communicate with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0054] As an example, based on actual application requirements, a confidential switch is selected for a confidential network.
[0055] When a target device needs to access a confidential network, a confidential network card is configured for the target device in advance, and the confidential network card configured for the target device will be connected to the port of the confidential switch.
[0056] When the confidential switch detects that a confidential network card is connected to a port of the confidential switch, it negotiates the port working mode with the confidential network card to establish a physical connection with the confidential network card.
[0057] In actual applications, a confidential switch can negotiate port operating modes with a confidential network interface card (NIC) according to the standard port operating mode negotiation process. For example, the confidential switch uses the auto-negotiation mechanism in the IEEE 802.3 standard to send the confidential network interface card (NIC) the port operating modes it supports. The confidential network interface card uses the auto-negotiation mechanism in the IEEE 802.3 standard to send the confidential switch the port operating modes it supports. The confidential switch and NIC negotiate and select a port operating mode from all supported port operating modes, resulting in the negotiated port operating mode.
[0058] The confidential switch determines whether the confidential switch has successfully established a physical connection with the confidential network card. If it is determined that the physical connection with the confidential network card is successfully established, it is considered that from the physical layer, the confidential switch supports communication with the confidential network card. At this time, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. If it is determined that the physical connection with the confidential network card fails, it is considered that from the physical layer, the confidential switch does not support communication with the confidential network card. At this time, the step of determining whether the confidential switch has successfully established a physical connection with the confidential network card can be returned.
[0059] It should be noted that a confidential network card refers to a network interface card (NIC) used to process confidential information, which has a unique identity information, such as the unique identification number of the chip inside the confidential network card.
[0060] In actual applications, the confidential switch can determine whether the confidential switch has successfully established a physical connection with the confidential network card by identifying the port status of the confidential switch. For example, if the confidential switch identifies that the port status of the confidential switch is active, such as the "UP" state, then it is determined that the confidential switch has successfully established a physical connection with the confidential network card. If the confidential switch identifies that the port status of the confidential switch is inactive, such as the "DOWN" state, then it is determined that the confidential switch has failed to establish a physical connection with the confidential network card.
[0061] If the identity information authentication of the confidential network card is successful, the confidential switch considers that the target device where the confidential network card is located is a confidential device, and allows the confidential switch to communicate with the target device where the confidential network card is located through the confidential network card. If the identity information authentication of the confidential network card fails, the confidential switch considers that the target device where the confidential network card is located is not a confidential device, and refuses the confidential switch to communicate with the target device where the confidential network card is located through the confidential network card.
[0062] Existing network switches mainly use any of the following methods to authenticate the identity of connected terminal devices. The first method is to obtain the MAC (Media Access Control) address of the connected terminal device at the data link layer, and determine whether to allow communication with the connected terminal device based on a pre-stored whitelist or blacklist. The second method is to obtain login information such as the user name and password based on the IP address of the connected terminal device at the network layer, and determine whether to allow communication with the connected terminal device based on the verification result of the login information. In the process of authenticating the identity of the connected terminal device, the existing network switch still needs to rely on communication with the connected terminal device, lacks a strict and effective authentication mechanism, and easily leads to non-confidential devices arbitrarily accessing the network switch to access the confidential network, seriously threatening the network security of the confidential network. By pre-configuring a confidential network card for the target device, introducing a confidential switch to first establish a physical connection with the connected confidential network card, authenticating the identity information of the confidential network card at the physical layer, and then choosing whether to allow communication with the target device where the confidential network card is located through the confidential network card based on the authentication result, the confidential switch can be used to indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly restricted, and communication with the target device is not supported at the data link layer and network layer above the physical layer, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0063] In the embodiment of the present application, a confidential network card is configured for the target device in advance. When the confidential switch detects that a confidential network card is connected to the port of the confidential switch, the confidential switch negotiates the port working mode with the confidential network card to establish a physical connection with the confidential network card. When the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. When the identity information of the confidential network card is successfully authenticated, the confidential network card is used to communicate with the target device where the confidential network card is located according to the negotiated port working mode. The confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0064] In an optional embodiment, the authentication of the identity information of the confidential network card includes: obtaining the identity information of multiple authorized network cards; comparing the identity information of the confidential network card with the identity information of each of the multiple authorized network cards; when the identity information of the confidential network card is consistent with the identity information of any of the multiple authorized network cards, determining that the authentication of the identity information of the confidential network card is successful; when the identity information of the confidential network card is inconsistent with the identity information of multiple authorized network cards, determining that the authentication of the identity information of the confidential network card has failed.
[0065] As an example, in order to improve the efficiency of the confidential switch in authenticating the identity information of the confidential network card, the identity information of multiple authorized network cards may be pre-stored in the confidential switch.
[0066] After obtaining the identity information of the confidential network card, the confidential switch retrieves the identity information of multiple authorized network cards and compares the identity information of the confidential network card with the identity information of each authorized network card in the multiple authorized network cards. If the identity information of the confidential network card is consistent with the identity information of any authorized network card in the multiple authorized network cards, the confidential network card is considered to be this authorized network card, and the identity information authentication of the confidential network card is determined to be successful. If the identity information of the confidential network card is inconsistent with the identity information of multiple authorized network cards, the confidential network card is considered to be unauthorized, and the identity information authentication of the confidential network card is determined to be failed.
[0067] In the embodiment of the present application, the confidential switch compares the identity information of the confidential network card with the identity information of each authorized network card in multiple authorized network cards. When the identity information of the confidential network card is consistent with the identity information of any authorized network card in the multiple authorized network cards, it is determined that the identity information authentication of the confidential network card is successful. When the identity information of the confidential network card is inconsistent with the identity information of multiple authorized network cards, it is determined that the identity information authentication of the confidential network card fails. This can effectively improve the authentication efficiency of the confidential switch for the identity information of the confidential network card.
[0068] In an optional embodiment, the identity information of the plurality of authorized network cards includes identity information of at least one network card authorized by the trusted server.
[0069] As an example, according to actual application requirements, a trusted server is selected based on the collected identity information of multiple network cards.
[0070] The trusted server performs trusted authentication on the identity information of each network card among the multiple network cards. If the identity information authentication of the network card is successful, the network card is authorized and allowed to participate in accessing the confidential network. If the identity information authentication of the network card fails, the network card is not authorized and is denied access to the confidential network, thereby determining the identity information of at least one authorized network card and sending the identity information of at least one authorized network card to the confidential switch, so that the confidential switch can receive and store the identity information of at least one network card authorized by the trusted server.
[0071] In an optional implementation of this embodiment, the trusted server can issue configuration instructions to the confidential switch based on the RADIUS or EAPOL protocol, triggering the confidential switch to identify the port as a trusted access port, not allowing the port to serve as the source of traffic mirroring, and preventing the leakage of encrypted traffic mirroring.
[0072] In the embodiment of the present application, the confidential switch obtains the identity information of at least one network card authorized by the trusted server, thereby introducing a trusted server and accurately determining whether to authorize the network card based on the trusted authentication mechanism, thereby ensuring that the confidential switch accurately authenticates the identity information of the confidential network card, which is conducive to further ensuring the network security of the confidential network.
[0073] In an optional embodiment, the method of communicating with the target device where the confidential network card is located through the confidential network card in accordance with the negotiated port working mode includes: when the negotiated port working mode meets the preset re-negotiation conditions, renegotiating the port working mode with the confidential network card to determine the target port working mode; and communicating with the target device through the confidential network card in accordance with the target port working mode.
[0074] For example, in actual application scenarios, if a confidential switch is unsure of the security of the target device where the confidential network card is located, the port operating mode negotiated with the confidential network card may not be the optimal port mode supported by the confidential switch and the confidential network card. To improve communication efficiency between the confidential switch and the target device where the confidential network card is located, renegotiation conditions can be set in advance based on the optimal port mode supported by the confidential switch and the confidential network card.
[0075] The confidential switch determines whether the negotiated port working mode meets the preset re-negotiation conditions. If the negotiated port working mode meets the preset re-negotiation conditions, it is considered that the negotiated port working mode is not the optimal port working mode supported by the confidential switch and the confidential network card. At this time, the port working mode is renegotiated with the confidential network card to determine the target port working mode. According to the target port working mode, communication is carried out with the target device through the confidential network card. If the negotiated port working mode does not meet the preset re-negotiation conditions, it is considered that the negotiated port working mode is already the optimal port working mode supported by the confidential switch and the confidential network card. At this time, communication is carried out directly with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
[0076] In an embodiment of the present application, when the negotiated port operating mode meets a preset re-negotiation condition, the confidential switch renegotiates the port operating mode with the confidential network card, determines the target port operating mode, and communicates with the target device through the confidential network card according to the target port operating mode. This ensures that the confidential switch communicates with the target device through the confidential network card according to the optimal port operating mode supported by the confidential switch and the confidential network card, which is beneficial to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0077] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate; and the preset re-negotiation condition includes that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card.
[0078] As an example, in actual application scenarios, the port operating mode typically includes a port rate. Under the premise that the confidential switch is uncertain about the security of the target device where the confidential network card is located, in order to avoid frequent attacks, the port rate negotiated with the confidential network card may be the minimum port rate supported by the confidential switch and the confidential network card, rather than the maximum port rate supported by the confidential switch and the confidential network card. In order to improve the communication efficiency between the confidential switch and the target device where the confidential network card is located, renegotiation conditions can be pre-set for the maximum port supported by the confidential switch and the confidential network card. For example, the preset renegotiation conditions include the negotiated port rate being less than the maximum port rate supported by the confidential switch and the confidential network card.
[0079] When the identity information of the confidential network card is successfully authenticated, the confidential switch obtains the negotiated port working mode, where the negotiated port working mode includes the negotiated port rate. The confidential switch determines whether the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card. If the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card, it is determined that the negotiated port working mode meets the preset re-negotiation condition, and it is considered that the negotiated port working mode is not the optimal port working mode supported by the confidential switch and the confidential network card. At this time, the confidential switch renegotiates the port working mode with the confidential network card to determine the target port working mode. According to the target port working mode, the confidential network card communicates with the target device. If the negotiated port rate is equal to the maximum port rate supported by the confidential switch and the confidential network card, it is determined that the negotiated port working mode does not meet the preset re-negotiation condition, and it is considered that the negotiated port working mode is already the optimal port working mode supported by the confidential switch and the confidential network card. At this time, the confidential network card directly communicates with the target device where the confidential network card is located through the negotiated port working mode.
[0080] The embodiments of the present application take into account that the port working mode usually includes the port rate. By setting a preset re-negotiation condition including that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card, the confidential switch can quickly and accurately determine whether it is necessary to renegotiate the port working mode with the confidential network card to optimize the negotiated port working mode, and ensure that the confidential switch communicates with the target device through the confidential network card in accordance with the optimal port working mode supported by it and the confidential network card, which is conducive to improving the communication efficiency between the confidential switch and the target device where the confidential network card is located.
[0081] In an optional embodiment, the communicating with the target device through the confidential network card includes: triggering the confidential network card to open a network port, and communicating with the target device through the network port of the confidential network card.
[0082] As an example, when the identity information of the confidential network card is successfully authenticated, the confidential switch considers that the target device where the confidential network card is located is a confidential device, and allows the confidential switch to communicate with the target device where the confidential network card is located through the confidential network card. At this time, the confidential network card is triggered to open a network port, such as a general Ethernet port, and communicate with the target device where the confidential network card is located through the network port of the confidential network card.
[0083] In the embodiment of the present application, the confidential switch triggers the confidential network card to open the network port, and communicates with the target device where the confidential network card is located through the network port of the confidential network card, thereby ensuring the communication stability between the confidential switch and the target device where the confidential network card is located.
[0084] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
[0085] As an example, when the confidential switch detects that a confidential network card is connected to a port of the confidential switch, it negotiates with the confidential network card on a port working mode including port rate and duplex mode to establish a physical connection with the confidential network card.
[0086] In actual applications, a confidential switch can negotiate the port operating mode with a confidential network card according to the standard port operating mode negotiation process. For example, the confidential switch uses the auto-negotiation mechanism in the IEEE 802.3 standard to send the confidential network card the port speed and duplex mode supported by the confidential switch. The confidential network card uses the auto-negotiation mechanism in the IEEE 802.3 standard to send the confidential switch the port speed and duplex mode supported by the confidential network card. The confidential switch and the confidential network card then negotiate to select a port speed from all supported port speeds and a duplex mode from all supported duplex modes. The negotiated port operating mode is then determined to include the negotiated port speed and duplex mode.
[0087] In the embodiment of the present application, the confidential switch and the confidential network card negotiate a port working mode including port rate and duplex mode, so that the confidential switch can subsequently strictly follow the negotiated port working mode and communicate with the target device where the confidential network card is located through the confidential network card, which is beneficial to further ensure the network security of the confidential network.
[0088] Please see Figure 2 , Figure 2 This is a schematic diagram of the structure of a confidential switch port communication processing device provided in the second embodiment of the present application. The second embodiment of the present application provides a confidential switch port communication processing device, which is applied to a confidential switch; the device includes: a negotiation module 201, which is used to negotiate the port working mode with the confidential network card when it is detected that a confidential network card is connected to a port of the confidential switch, so as to establish a physical connection with the confidential network card; an authentication module 202, which is used to obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card when the physical connection with the confidential network card is successfully established; and a communication module 203, which is used to communicate with the target device where the confidential network card is located through the confidential network card in accordance with the negotiated port working mode when the identity information of the confidential network card is successfully authenticated.
[0089] In an optional embodiment, the authentication of the identity information of the confidential network card includes: obtaining the identity information of multiple authorized network cards; comparing the identity information of the confidential network card with the identity information of each of the multiple authorized network cards; when the identity information of the confidential network card is consistent with the identity information of any of the multiple authorized network cards, determining that the authentication of the identity information of the confidential network card is successful; when the identity information of the confidential network card is inconsistent with the identity information of multiple authorized network cards, determining that the authentication of the identity information of the confidential network card has failed.
[0090] In an optional embodiment, the identity information of the plurality of authorized network cards includes identity information of at least one network card authorized by the trusted server.
[0091] In an optional embodiment, the method of communicating with the target device where the confidential network card is located through the confidential network card in accordance with the negotiated port working mode includes: when the negotiated port working mode meets the preset re-negotiation conditions, renegotiating the port working mode with the confidential network card to determine the target port working mode; and communicating with the target device through the confidential network card in accordance with the target port working mode.
[0092] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate; and the preset re-negotiation condition includes that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card.
[0093] In an optional embodiment, the communicating with the target device through the confidential network card includes: triggering the confidential network card to open a network port, and communicating with the target device through the network port of the confidential network card.
[0094] In an optional embodiment, the negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
[0095] The implementation process of the functions and effects of each module in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.
[0096] Please see Figure 3 , Figure 3 This is a schematic diagram of the structure of a confidential switch provided in the third embodiment of the present application. The third embodiment of the present application provides a confidential switch 30, comprising a processor 301, a memory 302, and a computer program stored in the memory 302 and configured to be executed by the processor 301; when the processor 301 executes the computer program, it implements the method described in the first embodiment of the present application and can achieve the same beneficial effects as described above.
[0097] In which, when the processor 301 reads the computer program from the memory 302 through the bus 303 and executes the computer program, it can implement the method of any embodiment included in the method described in the first embodiment of the present application.
[0098] Processor 301 can process digital signals and can include various computing architectures, such as a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, processor 301 can be a microprocessor.
[0099] The memory 302 can be used to store instructions executed by the processor 301 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all functions of one or more modules described in the embodiments of this application. The processor 301 of the embodiment of the present disclosure can be used to execute the instructions in the memory 302 to implement the method described in the first embodiment of this application. The memory 302 includes dynamic random access memory, static random access memory, flash memory, optical storage, or other memory known to those skilled in the art.
[0100] Please see Figure 4 , Figure 4 A structural diagram of a confidential switch port communication processing system provided in the fourth embodiment of the present application. The fourth embodiment of the present application provides a confidential switch port communication processing system, comprising a confidential switch 401 and at least one target device 402; each target device 402 in the at least one target device 402 is configured with a confidential network card; the confidential network card configured in each target device 402 is used to access the port of the confidential switch 401; the confidential switch 401 is used to: upon detecting that a confidential network card is connected to the port of the confidential switch 401, negotiate a port working mode with the confidential network card to establish a physical connection with the confidential network card; upon successfully establishing a physical connection with the confidential network card, obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card; upon successfully authenticating the identity information of the confidential network card, communicate with the target device 402 where the confidential network card is located through the confidential network card in accordance with the negotiated port working mode.
[0101] The implementation process of the functions and effects of the confidential switch in the above system is detailed in the implementation process of the corresponding steps in the above method, which will not be repeated here.
[0102] The fifth embodiment of the present application provides a computer program product, which includes instructions. When the instructions are executed by a computer, the computer implements the method described in the first embodiment of the present application and can achieve the same beneficial effects.
[0103] The method described in the first embodiment of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the processes or functions described in each embodiment of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model), or other programmable device.
[0104] A computer program or instruction can be stored in a computer-readable storage medium or transferred from one computer-readable storage medium to another. For example, a computer program or instruction can be transferred from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. A computer-readable storage medium can be any available medium that can be accessed by a computer, or a data storage device such as a server or data center that integrates one or more available media. Available media can be magnetic media, such as floppy disks, hard disks, or magnetic tapes; optical media, such as digital video disks; or semiconductor media, such as solid-state drives. The computer-readable storage medium can be volatile or non-volatile, or can include both volatile and non-volatile types of storage media.
[0105] The sixth embodiment of the present application provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method described in the first embodiment of the present application, and can achieve the same beneficial effects as the method described in the first embodiment of the present application.
[0106] In summary, the embodiments of the present application provide a method, device, confidential switch, and system for processing confidential switch port communications. The method is applied to a confidential switch; the method includes: upon detecting that a confidential network card is connected to a port of the confidential switch, negotiating a port operating mode with the confidential network card to establish a physical connection with the confidential network card; upon successfully establishing a physical connection with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; upon successfully authenticating the identity information of the confidential network card, communicating with the target device where the confidential network card is located through the confidential network card in accordance with the negotiated port operating mode. In the embodiment of the present application, a confidential network card is configured for the target device in advance. When the confidential switch detects that a confidential network card is connected to the port of the confidential switch, the confidential switch negotiates the port working mode with the confidential network card to establish a physical connection with the confidential network card. When the physical connection with the confidential network card is successfully established, the identity information of the confidential network card is obtained and the identity information of the confidential network card is authenticated. When the identity information of the confidential network card is successfully authenticated, the confidential network card is used to communicate with the target device where the confidential network card is located according to the negotiated port working mode. The confidential switch can indirectly authenticate the identity information of the target device by authenticating the identity information of the confidential network card at the physical layer, ensuring that before the identity information of the target device is successfully authenticated, communication with the confidential network card at the physical layer is strictly limited, and communication with the target device at the data link layer and network layer above the physical layer is not supported, effectively preventing non-confidential devices from arbitrarily accessing the confidential switch to access the confidential network, thereby ensuring the network security of the confidential network.
[0107] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.
[0108] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.
[0109] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, read-only memories (ROM), random access memories (RAM), magnetic disks or optical disks.
[0110] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.
Claims
1. A method for processing confidential switch port communications, characterized in that: Applied to a confidential switch; the method includes: When detecting that a confidential network card is connected to a port of the confidential switch, negotiating a port working mode with the confidential network card to establish a physical connection with the confidential network card; When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; The authenticating the identity information of the confidential network card includes: Obtaining identity information of multiple authorized network cards; wherein the identity information of the multiple authorized network cards includes identity information of at least one network card authorized by the trusted server; Comparing the identity information of the confidential network card with the identity information of each authorized network card in the plurality of authorized network cards; When the identity information of the confidential network card is consistent with the identity information of any authorized network card among the multiple authorized network cards, determining that the identity information authentication of the confidential network card is successful; When the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, determining that the identity information authentication of the confidential network card fails; When the identity information authentication of the confidential network card is successful, communication is performed with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
2. The method according to claim 1, characterized in that The method of communicating with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode includes: When the negotiated port operating mode meets the preset re-negotiation condition, renegotiate the port operating mode with the confidential network card to determine the target port operating mode; According to the target port working mode, communication is performed with the target device through the confidential network card.
3. The method according to claim 2, characterized in that The negotiated port working mode includes a negotiated port rate; the preset re-negotiation condition includes that the negotiated port rate is less than the maximum port rate supported by the confidential switch and the confidential network card.
4. The method according to claim 1, wherein The communicating with the target device through the confidential network card includes: Trigger the confidential network card to open the network port, and communicate with the target device through the network port of the confidential network card.
5. The method according to any one of claims 1 to 4, characterized in that The negotiated port operating mode includes a negotiated port rate and a negotiated duplex mode.
6. A confidential switch port communication processing device, characterized in that: Applicable to confidential switches; the device includes: a negotiation module configured to, upon detecting that a confidential network card is connected to a port of the confidential switch, negotiate a port operating mode with the confidential network card to establish a physical connection with the confidential network card; an authentication module, configured to obtain the identity information of the confidential network card and authenticate the identity information of the confidential network card when a physical connection is successfully established with the confidential network card; The authenticating the identity information of the confidential network card includes: Obtaining identity information of multiple authorized network cards; wherein the identity information of the multiple authorized network cards includes identity information of at least one network card authorized by the trusted server; Comparing the identity information of the confidential network card with the identity information of each authorized network card in the plurality of authorized network cards; When the identity information of the confidential network card is consistent with the identity information of any authorized network card among the multiple authorized network cards, determining that the identity information authentication of the confidential network card is successful; When the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, determining that the identity information authentication of the confidential network card fails; The communication module is used to communicate with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode when the identity information of the confidential network card is successfully authenticated.
7. A confidential switch, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor; when the processor executes the computer program, the method according to any one of claims 1 to 5 is implemented.
8. A confidential switch port communication processing system, characterized in that: It includes a confidential switch and at least one target device; each target device in the at least one target device is configured with a confidential network card; The confidential network card configured for each target device is used to access the port of the confidential switch; The confidential switch is used to: When detecting that a confidential network card is connected to a port of the confidential switch, negotiating a port working mode with the confidential network card to establish a physical connection with the confidential network card; When a physical connection is successfully established with the confidential network card, obtaining the identity information of the confidential network card and authenticating the identity information of the confidential network card; The authenticating the identity information of the confidential network card includes: Obtaining identity information of multiple authorized network cards; wherein the identity information of the multiple authorized network cards includes identity information of at least one network card authorized by the trusted server; Comparing the identity information of the confidential network card with the identity information of each authorized network card in the plurality of authorized network cards; When the identity information of the confidential network card is consistent with the identity information of any authorized network card among the multiple authorized network cards, determining that the identity information authentication of the confidential network card is successful; When the identity information of the confidential network card is inconsistent with the identity information of the multiple authorized network cards, determining that the identity information authentication of the confidential network card fails; When the identity information authentication of the confidential network card is successful, communication is performed with the target device where the confidential network card is located through the confidential network card according to the negotiated port working mode.
Citation Information
Patent Citations
Network card driving method and device, and storage medium
CN108712290A
Authentication method of trusted computing equipment, equipment and server
CN116707758A