Data detection system of physical isolation network
By setting up storage servers and edge gateways in each network group of the physically isolated network, and using a unified data acquisition and monitoring system, the problem of high resource cost of deploying detection systems in the physically isolated network shooting range is solved, and safe and efficient data detection is achieved.
Patent Information
- Application Number
- CN202510466557.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-04-15
AI Technical Summary
The physically isolated network shooting range deployment method requires maintenance of each isolated network separately, resulting in a high resource cost for deploying the detection system.
A data detection system for physically isolated networks is designed. By setting up a storage server and an edge gateway in each network group, and using a single data collector to collect and transmit data to multiple network devices in one-way, the central monitoring server uniformly reads the network monitoring data through the central gateway.
Reduces the resource cost of deploying data detection systems in physically isolated network shooting ranges, while improving the security of data acquisition.
Smart Images

Figure CN119996089A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a data detection system for a physically isolated network. Background Art
[0002] In order to improve the security of daily network communications, some virtualization technologies such as network ranges for simulating cyberspace have also been generated and developed. Simulated attacks and defense measures are carried out in these virtual networks, thereby improving the defense means and defense strength of defense measures in daily actual communication networks. In order to further improve the confrontation of simulated network attack defense in virtual network space and ensure the security of infrastructure in the network range, each network is usually physically isolated, that is, the network is physically divided into parts that are not directly connected to each other to enhance data security and system reliability. However, this physically isolated network range deployment method usually requires a separate maintenance of a corresponding supervision system for each isolated network, which makes the resource cost of deploying the detection system relatively high. Summary of the invention
[0003] An embodiment of the present application provides a data detection system for a physically isolated network, which can reduce the resource cost of deploying the data detection system in a physically isolated network target range.
[0004] To achieve the above-mentioned purpose, a first aspect of an embodiment of the present application provides a data detection system for a physically isolated network, the system comprising: A plurality of network groups, each of which includes a plurality of network devices and data collectors, wherein the network devices include at least one of a server, a security device, a routing and switching network device, and data between each two network groups are not interoperable; The edge of each network group is provided with a corresponding storage server and an edge gateway; The data collector is used to collect network monitoring data of the plurality of network devices in the corresponding network group in real time, and transmit the network monitoring data unidirectionally to the monitoring service program of the corresponding edge gateway, and then the monitoring service program remotely persists the data to the storage server; A central monitoring server, wherein the central monitoring server is used to read the network monitoring data in the associated storage server from the edge gateway of each of the network groups.
[0005] In some embodiments, the data detection system further includes a central gateway associated with the central monitoring server; Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the central monitoring server is also used to generate a self-signed certificate between the central gateway and the edge gateway, and send the self-signed certificate to the central gateway, and send the self-signed certificate to the edge gateway via an offline medium.
[0006] In some embodiments, before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution step of the edge gateway further includes: Obtaining the self-signed certificate and verifying the self-signed certificate to obtain a certificate verification result; When the certificate verification result indicates that the self-signed certificate is correct, the self-signed certificate is parsed to obtain the central gateway identifier and the identity authentication information of the edge gateway; Based on the central gateway identifier and the identity authentication information, establishing an encrypted tunnel between the edge gateway and the central gateway; An encryption key is generated based on the central gateway identifier and the identity authentication information.
[0007] In some embodiments, when the edge gateway executes the step of generating an encryption key based on the central gateway identifier and the identity authentication information, the execution steps of the edge gateway include: Performing hash processing based on the central gateway identifier to generate an initial key; Performing normalization and splicing processing on the edge gateway identifier of the edge gateway and the identity authentication information to generate a dynamic factor; Performing hash processing based on the dynamic factor to generate a dynamic key; The dynamic key and the initial key are subjected to XOR confusion processing to generate the encryption key.
[0008] In some embodiments, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution steps of the edge gateway include: Obtaining a network monitoring data acquisition request issued by the central gateway; Determining target network monitoring data from the network monitoring data based on the network monitoring data acquisition request, encrypting the target network monitoring data based on the encryption key, and generating encrypted data and a corresponding authentication tag; Based on the combination of the encrypted data and the authentication tag, combined encrypted network monitoring data is generated, and the combined encrypted network monitoring data is transmitted to the central gateway through the encrypted tunnel, so that the central gateway decrypts the combined encrypted network monitoring data and then transmits the target network monitoring data to the central monitoring server.
[0009] In some embodiments, when the edge gateway performs the encryption processing of the target network monitoring data based on the encryption key to generate encrypted data and a corresponding authentication tag, the execution steps include: Obtaining a nonlinear mapping table and generating a dislocation processing identifier; Based on the nonlinear mapping table, nonlinearly replace the target network monitoring data to generate nonlinear network monitoring data; Based on the dislocation processing identifier and the encryption key, performing dislocation encryption processing on the nonlinear network monitoring data to obtain the encrypted data; The authentication tag is generated based on the mapping table identifier of the nonlinear mapping table and the misalignment processing identifier.
[0010] In some embodiments, the dislocation processing identifier includes a row shift identifier and a column mixing identifier. When the edge gateway performs the dislocation encryption processing on the nonlinear network monitoring data based on the dislocation processing identifier and the encryption key to obtain the encrypted data, the execution steps include: Selecting target row data from the nonlinear network monitoring data based on the row shift identifier to perform row shift to obtain first shift data; Acquire a mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform a matrix operation on the target column data and the mixing matrix to obtain second shifted data; The second shifted data is XOR-ed with the encryption key to obtain the encrypted data.
[0011] In some embodiments, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution steps of the central monitoring server include: Sending a network monitoring data acquisition request to the central gateway; Obtain target network monitoring data sent by the central gateway according to the network monitoring data acquisition request.
[0012] In some embodiments, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution steps of the central gateway include: Receiving the network monitoring data acquisition request sent by the central monitoring server; Sending a central gateway identifier and the network monitoring data acquisition request to the edge gateway through the encrypted tunnel; Obtaining the combined encrypted network monitoring data sent by the edge gateway according to the network monitoring data acquisition request; Decoding the encrypted data in the combined encrypted network monitoring data based on the authentication tag in the combined encrypted network monitoring data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request; The target network monitoring data is sent to the central monitoring server.
[0013] In some embodiments, when the data collector collects network monitoring data of the plurality of network devices in the corresponding network group in real time, the steps include: When the current moment reaches a preset acquisition period, determining at least one target data type corresponding to the preset acquisition period; Collecting real-time type data corresponding to all the target data types from the multiple network devices in the network group; The network monitoring data is obtained based on all the real-time type data.
[0014] In some embodiments, after the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the central monitoring server further performs the following steps: Integrate and process all the network monitoring data to obtain integrated network monitoring data; The integrated network monitoring data is aggregated and analyzed to obtain analysis and processing data, and the analysis and processing data is displayed in a graphical form.
[0015] The data detection system of the physically isolated network proposed in the embodiment of the present application comprises: a plurality of network groups, each network group comprises a plurality of network devices and a data collector, the network devices comprise at least one of a server, a security device, a routing and a switching network device, the data between each two network groups are not interoperable, a corresponding storage server and an edge gateway are arranged at the edge of each network group, the data collector is used for collecting the network monitoring data of the plurality of network devices in the corresponding network group in real time, and transmitting the network monitoring data unidirectionally to the monitoring service program of the corresponding edge gateway, which is then remotely persisted to the storage server by the monitoring service program; a central monitoring server, the central monitoring server is used for reading the network monitoring data in the associated storage server from the edge gateway of each network group. In the embodiment of the present application, a storage server and an edge gateway are provided in each network group corresponding to the non-intercommunication of data, and then a single data collector realizing the collection function is used to collect data from multiple network devices in the network group, and the collected network monitoring data is transmitted to the storage server in the network group through the edge gateway for persistent storage by a push method. Finally, the central monitoring server reads data from the edge gateway of each network group through the central gateway, so that the same data detection system can be used to perform data detection on multiple physically isolated network groups at the same time, and the one-way data transmission process is used to make the monitoring service program of the edge gateway unable to access the network devices in the network group, thereby improving the security of data collection in the physically isolated network target range while reducing the resource cost of deploying the data detection system.
[0016] Other features and advantages of the present application will be described in the following description, and partly become apparent from the description, or understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a structural diagram of deploying multiple supervisory systems in a network-isolated network target range provided by an embodiment of the present application.
[0018] Figure 2 It is a structural diagram of a data detection system for a physically isolated network provided by another embodiment of the present application.
[0019] Figure 3 This is a schematic diagram of a three-layer structure in a data detection system provided in another embodiment of the present application.
[0020] Figure 4 This is a flow chart of data collection by a data collector provided by another embodiment of the present application.
[0021] Figure 5This is a flowchart of a central monitoring server sending a self-signed certificate to a central gateway and an edge gateway provided by another embodiment of the present application.
[0022] Figure 6 This is a flowchart of an edge gateway building an encryption tunnel and an encryption key provided by another embodiment of the present application.
[0023] Figure 7 This is a flowchart of an edge gateway generating an encryption key provided by another embodiment of the present application.
[0024] Figure 8 This is a flowchart of data encryption processing performed by an edge gateway provided by another embodiment of the present application.
[0025] Fig. 9 This is a flowchart of an edge gateway generating encrypted data and authentication tags provided by another embodiment of the present application.
[0026] Fig.10 This is a flowchart of an edge gateway performing staggered encryption processing using encrypted data provided by another embodiment of the present application.
[0027] Fig.11 This is a flowchart of data encryption acquisition performed by a central monitoring server provided in another embodiment of the present application.
[0028] Fig.12 This is a flowchart of data encryption acquisition performed by a central gateway provided in another embodiment of the present application.
[0029] Fig.13 This is a flowchart of data integration and analysis performed by a central monitoring server provided in another embodiment of the present application.
[0030] Fig.14 This is a schematic diagram of the hardware structure of an electronic device provided in yet another embodiment of the present application. DETAILED DESCRIPTION
[0031] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0032] It should be noted that although the functional modules are divided in the device schematic and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart.
[0033] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as those commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0034] In order to improve the security of daily network communications, some virtualization technologies such as network ranges for simulating cyberspace have also been generated and developed. Simulated attacks and defense measures are carried out in these virtual networks, thereby improving the defense means and defense strength of defense measures in daily actual communication networks. In order to further improve the confrontation of simulated network attack defense in virtual network space and ensure the security of infrastructure in the network range, each network is usually physically isolated, that is, the network is physically divided into parts that are not directly connected to each other to enhance data security and system reliability. Figure 1 , is a schematic diagram of a structure of deploying multiple supervisory systems in a network-isolated network range provided in an embodiment of the present application, such as Figure 1 As shown in , this physically isolated network range deployment method usually requires a corresponding monitoring system to be maintained for each isolated network, which makes the resource cost of deploying the detection system relatively high.
[0035] In order to reduce the resource cost of deploying a data detection system in a physically isolated network target range, the embodiment of the present application is equipped with a storage server and an edge gateway in each network group corresponding to the non-intercommunication of data, and then a single data collector that implements the collection function is used to collect data from multiple network devices in the network group, and the collected network monitoring data is transmitted to the storage server in the network group through the edge gateway for persistent storage by a push method. Finally, the central monitoring server reads data from the edge gateway of each network group through the central gateway, so that the same data detection system can be used to perform data detection on multiple physically isolated network groups at the same time, and the one-way data transmission process is used to make the monitoring service program of the edge gateway unable to access the network devices in the network group, thereby improving the security of data collection in the physically isolated network target range while reducing the resource cost of deploying the data detection system.
[0036] The data detection system for a physically isolated network provided by an embodiment of the present application will be further described below. Figure 2 , is a schematic diagram of a data detection system for a physically isolated network provided in an embodiment of the present application. Figure 2As shown in , the physically isolated network consists of multiple network groups (such as network group 1, network group 2, ... network group N) whose data are not interoperable and a central network. Each network group includes multiple network devices and data collectors for data transmission, and an edge gateway and a storage server (such as storage server 1 in network group 1) are set at the edge of each network group. The central network includes a central monitoring server and a central gateway, and the central gateway includes functions such as a central firewall and NAT.
[0037] Reference Figure 3 , is a schematic diagram of a three-layer structure in a data detection system provided in an embodiment of the present application. Figure 3 As shown in the data detection system, it is divided into three layers, including the isolated network layer, the edge layer and the central network layer. The isolated network layer is used to collect network monitoring data of devices inside the isolated network; the edge layer is used to aggregate and store network monitoring data in the current isolated network; the central network layer is used to aggregate, analyze and display network monitoring data of all isolated networks.
[0038] The isolated network layer includes multiple network groups that are isolated from each other (i.e., data is not interoperable). The network group includes multiple network devices, which are usually servers, security devices, routing and switching network devices. Data collectors are deployed on the network devices that need to be monitored in the isolated network of the network group, and are equipped with corresponding monitoring service addresses on the edge gateway. The data collector sends the collected indicator data to the edge layer in a one-way manner at a fixed time or period, and stores it on the storage server through the monitoring service program on the edge gateway.
[0039] In the edge layer, an edge gateway and a storage server are set up at the edge of each network group. Security control programs and monitoring service programs are deployed on the edge gateway, and multiple storage repositories are deployed in a cluster on the storage server. The security control program on the edge gateway establishes an encrypted tunnel with the central gateway through a virtual interface. The monitoring service program on the edge gateway writes the network monitoring data to the storage repository through the remote read and write interface of the storage repository. The monitoring service program is used to obtain, cache and forward the network monitoring data of the network group, and the security control program is used to ensure the security of the monitoring data transmission between each network group and the central network.
[0040] Among them, the security control program deployed by the edge gateway includes an identity authentication module, an access control module and a monitoring data encryption module. The identity authentication module is used to ensure that the central gateway corresponding to the authorized central monitoring server can access the monitoring service program on the edge gateway, and extract the corresponding central gateway identification and identity authentication information. The access control module is used to set the one-way transmission strategy from the network device to the monitoring service program on the edge gateway and authorize the central gateway to access the monitoring service program of the edge gateway. The monitoring data encryption module is used to establish an encrypted tunnel from the edge gateway to the central gateway and encrypt the network monitoring data. The encrypted tunnels from the edge gateway to the central gateway corresponding to each network group are not interconnected and do not affect each other.
[0041] In the central network layer, security control and monitoring service programs are deployed on the central gateway, and a unified monitoring system is deployed on the central server. The central gateway provides a virtual interface to establish an encrypted tunnel with the edge gateway corresponding to each network group. The monitoring service program on the central gateway obtains the network monitoring data of all network groups through remote reading, aggregates and analyzes them, and presents them in a visual way through the unified monitoring system.
[0042] The data collector corresponding to each network group is used to collect network monitoring data of multiple network devices in the network group in real time during the data transmission process, and transmit the collected network monitoring data unidirectionally to the edge gateway in the network group, and the edge gateway transmits it to the associated storage server for persistent storage, so that the central monitoring server can read the network monitoring data in the network group from the edge gateway of each network group in the future, so that a storage server and an edge gateway are set in each network group corresponding to the non-intercommunication of data, and then a single data collector that realizes the collection function is used to collect data from multiple network devices in the network group, and the collected network monitoring data is transmitted to the associated storage server through the edge gateway for persistent storage by pushing mode, and finally the central monitoring server reads the data from the edge gateway of each network group through the central gateway, so that the same data detection system is used to realize data detection of multiple physically isolated network groups at the same time, and the unidirectional data transmission process is used to make the monitoring service program of the edge gateway unable to access the network devices in the network group, thereby improving the security of data collection in the physically isolated network target range while reducing the resource cost of deploying the data detection system.
[0043] The data collector can be an open source tool like telegraf, or a self-developed agent. Then configure the network monitoring data upload path in each data collector of the network group, that is, the remote write interface of the monitoring service program deployed on the edge gateway of the corresponding network group. The data collector uploads the collected network monitoring data (such as CPU usage, memory usage, performance indicators, etc.) between network devices in the network group to the edge gateway regularly (or in real time) through the remote write interface of the monitoring service program, and transmits it to the corresponding storage server for storage through the edge gateway.
[0044] A remote repository is deployed on each storage server to store the network monitoring data sent by the data collector. The remote read-write module is configured in the yaml configuration file of the edge gateway's monitoring service program, and the read-write interface of the remote repository is filled in the read-write module. In addition, the edge gateway's monitoring service program receives the collected network monitoring data uploaded by the data collector in the network group, stores it persistently, and writes it to the remote repository through the remote repository's write interface.
[0045] Through the one-way NAT configuration of the edge gateway's monitoring service, each network device in the network group can access the monitoring service program on the edge gateway and upload the collected network monitoring data to the monitoring service program component of the edge gateway, while the monitoring service program component of the edge gateway cannot access each network device in the network group. This setting ensures the security of network devices and reduces the network attack surface.
[0046] In some embodiments, taking network group 1 as an example, the monitoring service program deployed on the edge gateway in the network group can be one instance or multiple instances, and each data collector is associated with a monitoring service program of the edge gateway. After collecting network monitoring data, each data collector in the network group 1 pushes the network monitoring data unidirectionally to the monitoring service program of the corresponding edge gateway, so that the monitoring service program transmits the network monitoring data to the associated storage server, so that the subsequent central monitoring server can read these network monitoring data from the storage server through the edge gateway.
[0047] When the data collector collects the network monitoring data of a plurality of network devices in the corresponding network group in real time, the execution steps include the following steps 401 to 403 .
[0048] Step 401: When the current moment reaches a preset acquisition period, at least one target data type corresponding to the preset acquisition period is determined.
[0049] Step 402: Collect real-time type data corresponding to all target data types from multiple network devices in the network group.
[0050] Step 403: Obtain network monitoring data based on all real-time type data.
[0051] Steps 401 to 403 are described in detail below.
[0052] In some embodiments, when the data collector performs data detection, it may also perform preset periodic data acquisition according to network changes in the network group, or it may perform periodic data acquisition according to the preset acquisition period set by the data period acquisition requirements of the central monitoring server, such as every five minutes, etc. When at the current moment, the clock in the data collector triggers the preset acquisition period, the target data type to be collected in the preset acquisition period is determined through a predefined monitoring indicator list (such as target_metrics.yaml), such as the CPU usage (cpu_usage) and memory usage (mem_utilization) of each network device, the number of TCP connections (tcp_connections) between network devices, bandwidth utilization (bandwidth_usage), throughput, etc.
[0053] The data collector then collects real-time type data corresponding to these target data types at the current moment from all network devices in the network group, and uses these real-time type data as network monitoring data, so as to transmit these network monitoring data to the storage server associated with the edge gateway for persistent storage.
[0054] Through the above steps 401 to 403, by utilizing the preset periodic data acquisition and collecting only key indicators, invalid data transmission is reduced and the reliability of data acquisition is improved. In addition, by utilizing the preset acquisition cycle and corresponding target type data that can be dynamically updated, flexible adaptation to new monitoring requirements can be achieved, thereby improving the data acquisition flexibility of the data detection system.
[0055] In some embodiments, in addition to deploying a monitoring service program service on the edge gateway of each network group, in order to further improve the data transmission security of the data detection system of the physically isolated network, and thereby improve the data confidentiality in simulated attack and defense scenarios in the network target range, it is also necessary to build an encrypted tunnel between the edge gateway and the central gateway, and generate an encryption key, so that the encryption key can be used to encrypt the network monitoring data subsequently, and the encrypted network monitoring data can be securely transmitted through the highly secure encryption tunnel.
[0056] The following will further describe how to build an encrypted tunnel between the central gateway and the edge gateway and generate encryption keys.
[0057] Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the central monitoring server also include the following step 501 .
[0058] Step 501: Generate a self-signed certificate between the central gateway and the edge gateway, send the self-signed certificate to the central gateway, and send the self-signed certificate to the edge gateway via an offline medium.
[0059] Step 501 is described in detail below.
[0060] In some embodiments, before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the central monitoring server first generates a self-signed certificate between the central gateway and the edge gateway, the self-signed certificate including the central gateway identifier, the edge gateway identifier and the identity authentication information of the monitoring service program of the edge gateway. Then the self-signed certificate is sent directly to the intermediate gateway, and the self-signed certificate is sent to each edge gateway via an offline medium (such as a USB flash drive or other tool) so that the self-signed certificate can be used to build an encrypted tunnel between the central gateway and the edge gateway, and generate a corresponding encryption key.
[0061] By setting strict access control policies, we ensure that only authorized central gateways can obtain data from the storage server through the edge gateway, ensuring the secure isolation of each isolated area.
[0062] Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the edge gateway also include the following steps 601 to 604.
[0063] Step 601: Obtain a self-signed certificate, and verify the self-signed certificate to obtain a certificate verification result.
[0064] Step 602: When the certificate verification result indicates that the self-signed certificate is correct, the self-signed certificate is parsed to obtain the central gateway identifier and the identity authentication information of the edge gateway.
[0065] Step 603: Based on the central gateway identification and identity authentication information, an encrypted tunnel is established between the edge gateway and the central gateway.
[0066] Step 604: Generate an encryption key based on the central gateway identifier and identity authentication information.
[0067] Steps 601 to 604 are described in detail below.
[0068] In some embodiments, before the central monitoring server is ready to read the network monitoring data in the storage server from the edge gateways of each physically isolated network group, in order to ensure communication security, the edge gateway will first perform a series of security preparation steps. Specifically, the edge gateway first obtains a self-signed certificate, verifies the self-signed certificate, and obtains a certificate verification result. The edge gateway receives the self-signed certificate delivered by the central monitoring server through an offline medium (such as a USB flash drive), and uses a pre-configured trusted root certificate or a built-in verification mechanism to verify the validity, integrity, and authenticity of the self-signed certificate to confirm whether the certificate is issued by a trusted source and has not been tampered with, thereby obtaining a certificate verification result.
[0069] When the certificate verification result indicates that the self-signed certificate is correct, that is, the self-signed certificate is credible, the edge gateway will further parse the certificate and extract key information from it, including the central gateway identifier of the central gateway (i.e., a unique identifier, such as the IP address or domain name of the central gateway) and the identity authentication information (e.g., a pre-shared key or a public key) used for the edge gateway to authenticate the identity. This information will be used for the subsequent establishment of encrypted tunnels and encryption keys.
[0070] After obtaining the central gateway identification and authentication information, the edge gateway will establish an encrypted tunnel between the edge gateway and the central gateway based on the central gateway identification and authentication information. That is, the edge gateway uses the central gateway identification as the target address, and in combination with the authentication information, establishes an encrypted tunnel with the central gateway through a preset security protocol (for example, IPsec, TLS / SSL, or VPN). This encrypted tunnel will be used to protect the transmission of subsequent network monitoring data and prevent the data from being eavesdropped or tampered with during transmission. This encrypted tunnel is limited to data transmission between the central gateway and the edge gateway, and other devices cannot access or monitor it.
[0071] Finally, the edge gateway generates an encryption key based on the central gateway identification and authentication information. The edge gateway uses the central gateway identification and authentication information to generate an encryption key for encrypting network monitoring data through a specific key derivation function (KDF) or key negotiation algorithm. The encryption key is generated dynamically and can adopt a "one report one secret" strategy, that is, a different key is used for each data transmission to improve security. The key generation process should ensure the randomness and uniqueness of the key and prevent key leakage. The generated encryption key will be used to encrypt the network monitoring data in the future to protect the confidentiality of the data. The following will further describe how to generate the encryption key.
[0072] Among them, when the edge gateway generates an encryption key based on the central gateway identification and identity authentication information, the execution steps of the edge gateway include the following steps 701 to 704.
[0073] Step 701: Generate an initial key by performing hash processing based on the central gateway identifier.
[0074] Step 702: normalize and concatenate the edge gateway identifier and identity authentication information of the edge gateway to generate a dynamic factor.
[0075] Step 703: Generate a dynamic key by performing hash processing based on the dynamic factor.
[0076] Step 704: Perform XOR confusion processing on the dynamic key and the initial key to generate an encryption key.
[0077] Steps 701 to 704 are described in detail below.
[0078] In some embodiments, in order to ensure the security of data transmission, the edge gateway needs to generate an encryption key for encrypting network monitoring data after establishing an encrypted tunnel with the central gateway. The edge gateway first generates an initial key by hashing the central gateway identifier. Specifically, the edge gateway uses a hash algorithm (such as SHA-256 or MD5) to hash the central gateway identifier to generate an initial key of a fixed length.
[0079] Next, the edge gateway concatenates its own edge gateway identity (i.e., its own unique identifier, such as its IP address or unique ID) with the authentication information previously parsed from the self-signed certificate (such as a pre-shared key or public key). To ensure the consistency of the concatenation results, the edge gateway identity and authentication information can be normalized, such as by unifying the encoding format, removing spaces or special characters, etc. The concatenated result is used as a dynamic factor to generate a dynamic key, increasing the randomness and security of the encryption key.
[0080] Afterwards, the edge gateway uses a hash algorithm (such as SHA-256 or MD5) to perform a hash operation on the generated dynamic factor to generate a dynamic key of fixed length. Since the dynamic factor contains the edge gateway identification and identity authentication information, the generated dynamic key has higher randomness and security, and can effectively prevent replay attacks and man-in-the-middle attacks.
[0081] Finally, the edge gateway performs an XOR operation on the generated initial key and the dynamic key to obtain the final encryption key. XOR operation is a simple obfuscation algorithm that can mix the characteristics of two keys to increase the complexity and security of the key. The generated encryption key will be used to encrypt the network monitoring data in the future to protect the confidentiality of the data. This combination of the initial key and the dynamic key implements the "one report, one secret" dynamic encryption strategy. Even if the initial key is leaked, the original data cannot be deduced through the dynamic key, thereby improving the security of the system.
[0082] Through the above steps 701 to 704, a fixed initial key is generated by hashing the central gateway identifier, which ensures the association between the encryption key and the central gateway and prevents the forgery of the key. The dynamic factor is generated by combining the edge gateway identifier and the identity authentication information, and the dynamic key is generated by hashing, so that the encryption key is dynamic and unique. Even if the central gateway identifier is leaked, the attacker cannot easily obtain the valid key because the key of each edge gateway is unique and changes over time. Finally, the dynamic key and the initial key are XOR-confused, which further increases the complexity and randomness of the encryption key, making the encryption key more difficult to crack or predict. This key generation mechanism that combines static identification and dynamic information effectively prevents security threats such as replay attacks and man-in-the-middle attacks, and ensures the confidentiality and integrity of the data transmission process from the edge gateway to the central gateway.
[0083] Through the above steps 501 and steps 601 to 604, the self-signed certificate is generated and distributed offline to the edge gateway through the central monitoring server, avoiding the risk of the self-signed certificate being stolen or tampered with during network transmission. The edge gateway obtains the certificate and verifies it to ensure the legitimacy of the identity of the communicating party. The edge gateway obtains the central gateway identification and the identity authentication information of the edge gateway by parsing the self-signed certificate, providing the necessary information for the subsequent establishment of an encrypted tunnel and the generation of encryption keys. An encrypted tunnel is established based on this information to ensure the confidentiality and integrity of subsequent data transmission. Finally, an encryption key is generated based on the same information to ensure that only an authorized central gateway can decrypt the data, further enhancing data security. This security mechanism based on self-signed certificates and offline distribution effectively protects the data security of physically isolated networks and prevents unauthorized access and data leakage.
[0084] In some embodiments, a monitoring service program is deployed on the central gateway of the central network, and is used to read the network monitoring data stored on the storage servers of all network groups through the edge gateways of the network groups. A remote reading module is configured in the yaml configuration file of the monitoring service program of the central gateway, and the reading interface of the monitoring service program of all edge gateways is filled in the reading module.
[0085] When the actual central monitoring server reads network monitoring data from the storage server through the edge gateway of each network group, in order to further improve the security and reliability of data transmission and to avoid being monitored by other network eavesdropping devices during the data transmission process, the network monitoring data will be encrypted at the edge gateway using the generated encryption key in this embodiment before transmission, as described below.
[0086] When the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the edge gateway include the following steps 801 to 803.
[0087] Step 801: Obtain a network monitoring data acquisition request sent by a central gateway.
[0088] Step 802: Determine target network monitoring data from the network monitoring data based on the network monitoring data acquisition request, encrypt the target network monitoring data based on the encryption key, and generate encrypted data and a corresponding authentication tag.
[0089] Steps 801 to 802 are described in detail below.
[0090] In some embodiments, after building an encrypted tunnel between the central gateway and each edge gateway, and each edge gateway generates an encryption key, when the central monitoring server needs to read the network monitoring data in the storage server from the edge gateway of each network group, the central monitoring server sends a data acquisition request to the edge gateway through the central gateway from the established encrypted tunnel. The request contains the range, timestamp or other filtering conditions of the requested data. The edge gateway receives and parses the request to determine the specific data that needs to be transmitted.
[0091] Afterwards, the edge gateway selects the target network monitoring data that meets the conditions from the locally stored network monitoring data according to the data acquisition request received in the network. Then, the edge gateway uses the encryption key generated previously to encrypt the target network monitoring data to generate encrypted data. At the same time, in order to ensure the integrity of the data, the edge gateway also generates an authentication tag corresponding to the encrypted data while using the encryption key for encryption processing.
[0092] The following will further describe how the edge gateway uses the encryption key to encrypt the target network monitoring data.
[0093] Among them, when the edge gateway performs encryption processing on the target network monitoring data based on the encryption key to generate encrypted data and a corresponding authentication tag, the execution includes the following steps 901 to 904.
[0094] Step 901: Obtain a nonlinear mapping table and generate a misalignment processing identifier.
[0095] Step 902: Based on the nonlinear mapping table, nonlinearly replace the target network monitoring data to generate nonlinear network monitoring data.
[0096] Step 903: Based on the dislocation processing identifier and the encryption key, the nonlinear network monitoring data is subjected to dislocation encryption processing to obtain encrypted data.
[0097] Step 904: Generate an authentication tag based on the mapping table identifier and the misalignment processing identifier of the nonlinear mapping table.
[0098] Steps 901 to 904 are described in detail below.
[0099] In some embodiments, after obtaining the encryption key, the specific edge gateway determines the nonlinear mapping table and the offset processing identifier corresponding to the current encryption processing, wherein the nonlinear mapping table is an S-Box (a multi-order lookup table), and the mapping table contains nonlinear mapping relationships of multiple character data. The offset processing identifier includes a row shift identifier and a column shift identifier. The row shift identifier includes target rows corresponding to multiple row transformation processes and corresponding processing methods, and the column shift identifier includes target columns corresponding to multiple column transformation processes and corresponding processing methods.
[0100] Next, nonlinear replacement is performed on each byte in the target network monitoring data based on the nonlinear mapping table to generate nonlinear network monitoring data. When FPGA is used in the edge gateway, the S-Box module can be used in parallel to accelerate the nonlinear replacement process.
[0101] After performing the nonlinear replacement processing, the edge gateway further performs dislocation encryption processing on the nonlinear network monitoring data based on the dislocation processing identifier and the encryption key to obtain encrypted data, as described in detail below.
[0102] Among them, when the edge gateway performs dislocation encryption processing on the nonlinear network monitoring data based on the dislocation processing identifier and the encryption key to obtain encrypted data, the following steps 1001 to 1003 are executed.
[0103] Step 1001: Select target row data from nonlinear network monitoring data based on a row shift identifier, perform row shift, and obtain first shift data.
[0104] Step 1002: Obtain a mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform a matrix operation on the target column data and the mixing matrix to obtain second shifted data.
[0105] Step 1003: Perform XOR processing on the second shifted data and the encryption key to obtain encrypted data.
[0106] Steps 1001 to 1003 are described in detail below.
[0107] In some embodiments, after obtaining the misalignment processing identifier, encryption key and nonlinear network monitoring data, the edge gateway first selects the target row data from the nonlinear network monitoring data based on the row shift identifier in the misalignment processing identifier to perform row shift to obtain the first shifted data, such as shifting the first row in the nonlinear network monitoring data left by 1 byte, shifting the second row right by 2 bytes, and so on.
[0108] Next, the edge gateway obtains the mixing matrix corresponding to the column shift identifier in the misalignment processing identifier, and then selects the target column data from the first shifted data based on the column shift identifier, and then performs matrix multiplication operation on the target column data and the mixing matrix to obtain the second shifted data. Finally, the obtained second shifted data and the encryption key are subjected to XOR confusion processing (XOR operation) again to obtain encrypted data with strong randomness and confidentiality.
[0109] Finally, the edge gateway uses the mapping table identifier and the dislocation processing identifier (including the row transformation identifier and the column transformation identifier) in the nonlinear mapping table to generate an authentication tag so that the subsequent receiving and conversion device can use the authentication tag to perform corresponding decryption processing on the encrypted data after receiving the encrypted data.
[0110] Through the above steps 901 to 904, and steps 1001 to 1003, the edge gateway significantly improves the security of the target network monitoring data through the synergy of dynamic nonlinear obfuscation and multi-level diffusion mechanism, and destroys the statistical characteristics of the network monitoring data by byte replacement based on the nonlinear mapping table to resist the side channel attack based on pattern analysis. The spatial diffusion effect is introduced by dynamic row shift and mixed matrix operation. The single-byte modification will cause chain changes in multiple columns of data, effectively suppressing differential attacks. Combined with the obfuscation parameters of the dynamic identifier (row shift identifier, column mixed identifier), the central monitoring server implements the "one report and one secret" dynamic encryption strategy in the process of reading the network monitoring data of the storage server associated with the edge gateway. Even if the key is leaked, the network monitoring data cannot be reversely deduced. Then, the authentication tag is used to generate a deep fusion of nonlinear mapping table features and dislocation identifiers, and data integrity protection and encryption process traceability are simultaneously realized to prevent replay attacks and middleman tampering, thereby greatly improving the data security of the data detection system of the physically isolated network.
[0111] Step 803: Generate combined encrypted network monitoring data based on the combination of encrypted data and authentication tag, and transmit the combined encrypted network monitoring data to the central gateway through an encrypted tunnel, so that the central gateway can decrypt the combined encrypted network monitoring data and transmit the target network monitoring data to the central monitoring server.
[0112] Step 803 is described in detail below.
[0113] In some embodiments, in order to ensure the security and integrity of network monitoring data during transmission, after completing data encryption to obtain encrypted network monitoring data and authentication tag generation, the edge gateway will further combine the encrypted data and authentication tag combination to combine the encrypted network monitoring data, and transmit the combined encrypted network monitoring data to the central gateway through the previously established encrypted tunnel, so that the central gateway can transmit the combined encrypted network monitoring data to the central monitoring server. This step combines the encrypted data with the authentication tag to form a complete and protected data packet, ensuring that the data will neither be eavesdropped (because it is encrypted) nor tampered with (because there is an authentication tag) during transmission. Transmission through an encrypted tunnel further ensures the security of data transmission and prevents threats such as man-in-the-middle attacks. As a transit, the central gateway receives the combined encrypted network monitoring data, decrypts it to obtain the target network monitoring data, and then safely forwards the target network monitoring data to the central monitoring server for subsequent analysis and processing.
[0114] In contrast, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution of the central monitoring server includes the following steps 1101 to 1102 .
[0115] Step 1101: Send a network monitoring data acquisition request to the central gateway.
[0116] Step 1101 is described in detail below.
[0117] In some embodiments, when the central monitoring server needs to obtain network monitoring data from the edge gateways of each physically isolated network group, the central monitoring server constructs a network monitoring data acquisition request containing the required data range, timestamp, data type, etc. according to a preset policy or user's instructions, and sends the network monitoring data acquisition request to the central gateway. The purpose of the request is to instruct the central gateway to obtain specific network monitoring data from the corresponding edge gateway so that the central monitoring server can perform subsequent analysis and processing.
[0118] Likewise, when the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the execution steps of the central gateway include the following steps 1201 to 1205.
[0119] Step 1201: Receive a network monitoring data acquisition request sent by a central monitoring server.
[0120] Step 1202: Send the central gateway identification and network monitoring data acquisition request to the edge gateway through the encrypted tunnel.
[0121] Step 1203: Obtain the combined encrypted network monitoring data sent by the edge gateway according to the network monitoring data acquisition request.
[0122] Step 1204: Decode the encrypted data in the combined encrypted network monitoring data based on the authentication tag in the combined encrypted network monitoring data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request.
[0123] Step 1205: Send the target network monitoring data to the central monitoring server.
[0124] Steps 1201 to 1205 are described in detail below.
[0125] In some embodiments, when the central monitoring server needs to obtain network monitoring data from the edge gateways of each physically isolated network group, the central gateway acts as an intermediate bridge and is responsible for securely forwarding requests and data. First, the central gateway receives the network monitoring data acquisition request issued by the central monitoring server, and sends the central gateway identifier and the network monitoring data acquisition request to the edge gateway through the established encrypted tunnel to ensure that the data is not eavesdropped or tampered with during transmission.
[0126] Next, after receiving the request, the edge gateway extracts the corresponding network monitoring data from the local storage according to the request content, encrypts and authenticates the tag, generates the combined encrypted network monitoring data and sends it back to the central gateway. The central gateway receives the combined encrypted data from the edge gateway and prepares for subsequent decryption and verification.
[0127] Afterwards, the central gateway uses the authentication tag in the combined encrypted data to generate a highly random encryption key, and then uses the encryption key and the authentication tag in the combined encrypted network monitoring data to decrypt the encrypted data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request.
[0128] Finally, the central gateway sends the decrypted target network monitoring data to the central monitoring server for subsequent analysis, processing and display. Through this series of steps, the central gateway transmits the request of the central monitoring server to the edge gateway under the premise of ensuring data security and integrity, and safely transmits the data returned by the edge gateway to the central monitoring server, thus completing the entire data acquisition process.
[0129] Step 1102: Obtain target network monitoring data sent by the central gateway according to the network monitoring data acquisition request.
[0130] Step 1102 is described in detail below.
[0131] In some embodiments, after the central monitoring server sends a network monitoring data acquisition request to the central gateway, the central monitoring server continues to monitor the connection between it and the central gateway. Once the central gateway completes the request, reception, verification and decryption of the edge gateway data and sends the final target network monitoring data back, the central monitoring server receives the data for subsequent analysis, storage, display or other related operations.
[0132] Finally, after reading the network monitoring data in the associated storage server from the edge gateway of each network group, the central monitoring server further performs the following steps 1301 to 1302 .
[0133] Step 1301: Integrate all network monitoring data to obtain integrated network monitoring data.
[0134] Step 1302: aggregate and analyze the integrated network monitoring data to obtain analysis and processing data, and display the analysis and processing data in a graphical form.
[0135] Steps 1301 to 1302 are described in detail below.
[0136] In some embodiments, after the central monitoring server obtains the network monitoring data sent by the monitoring service programs on all edge gateways through remote reading, it will integrate these network monitoring data to obtain integrated network monitoring data, and then aggregate and analyze the integrated network monitoring data to obtain analysis and processing data, and then display the analysis and processing data in a graphical form to present it to the operation and maintenance personnel, so as to improve the observability of data detection, thereby improving data processing efficiency and comprehensibility.
[0137] In some embodiments, the data detection system for physically isolated networks provided in the embodiments of the present application is not only applicable to the facilities of a network range, but also includes multiple specific application scenarios, such as sub-ranges and remote computer rooms. At the same time, the construction and use of the data detection system can also cover other related network environments to ensure safe and effective data processing and information exchange.
[0138] The present application also provides an electronic device, including: at least one memory; at least one processor; at least one program; The program is stored in the memory, and the processor executes the at least one program to implement the relevant steps and processes in the data detection system of the physical isolation network implemented in the present application. The electronic device can be any intelligent terminal including a mobile phone, a tablet computer, a personal digital assistant (PDA), a car computer, etc.
[0139] See also Fig.14 , Fig.14 The hardware structure of an electronic device of another embodiment is illustrated, and the electronic device includes: The processor 1401 may be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (Application Specific Integrated Circuit, ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application; The memory 1402 can be implemented in the form of ROM (Read Only Memory), static storage device, dynamic storage device or RAM (Random Access Memory). The memory 1402 can store operating systems and other applications. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1402, and the processor 1401 calls and executes the relevant steps in the data detection system of the physically isolated network of the embodiment of this application; Input / output interface 1403, used to implement information input and output; The communication interface 1404 is used to realize the communication interaction between the device and other devices. The communication can be realized through a wired manner (such as USB, network cable, etc.) or a wireless manner (such as mobile network, WIFI, Bluetooth, etc.); A bus 1405 that transmits information between various components of the device (e.g., the processor 1401, the memory 1402, the input / output interface 1403, and the communication interface 1404); The processor 1401 , the memory 1402 , the input / output interface 1403 and the communication interface 1404 are connected to each other in communication within the device via a bus 1405 .
[0140] An embodiment of the present application also provides a storage medium, which is a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the relevant step flow in the data detection system of the above-mentioned physically isolated network.
[0141] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0142] The embodiments described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.
[0143] Those skilled in the art will appreciate that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0144] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0145] Those skilled in the art will appreciate that all or some of the steps in the methods disclosed above, and the functional modules / units in the systems and devices may be implemented as software, firmware, hardware, or a suitable combination thereof.
[0146] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable where appropriate, so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device comprising a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.
[0147] It should be understood that in the present application, "at least one (item)" means one or more, and "plurality" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.
[0148] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the above units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. The mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0149] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0150] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0151] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including multiple instructions to enable a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (Read-Only Memory, referred to as ROM), random access memory (Random Access Memory, referred to as RAM), disk or optical disk and other media that can store programs.
[0152] The preferred embodiments of the present invention are described above with reference to the accompanying drawings, but the scope of the rights of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by a person skilled in the art without departing from the scope and essence of the present invention should be within the scope of the rights of the present invention.
Claims
1. A data detection system for a physically isolated network, characterized in that: The system comprises: A plurality of network groups, each of which includes a plurality of network devices and data collectors, wherein the network devices include at least one of a server, a security device, a routing and switching network device, and data between each two network groups are not interoperable; The edge of each network group is provided with a corresponding storage server and an edge gateway; The data collector is used to collect network monitoring data of the plurality of network devices in the corresponding network group in real time, and transmit the network monitoring data unidirectionally to the monitoring service program of the corresponding edge gateway, and then the monitoring service program remotely persists the data to the storage server; A central monitoring server, wherein the central monitoring server is used to read the network monitoring data in the associated storage server from the edge gateway of each of the network groups.
2. The data detection system for a physically isolated network according to claim 1, characterized in that: include: The data detection system also includes a central gateway associated with the central monitoring server; Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the central monitoring server is also used to generate a self-signed certificate between the central gateway and the edge gateway, and send the self-signed certificate to the central gateway, and send the self-signed certificate to the edge gateway via an offline medium.
3. The data detection system for physically isolated network according to claim 2, characterized in that: Before the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution step of the edge gateway further includes: Obtaining the self-signed certificate and verifying the self-signed certificate to obtain a certificate verification result; When the certificate verification result indicates that the self-signed certificate is correct, the self-signed certificate is parsed to obtain the central gateway identifier and the identity authentication information of the edge gateway; Based on the central gateway identifier and the identity authentication information, establishing an encrypted tunnel between the edge gateway and the central gateway; An encryption key is generated based on the central gateway identifier and the identity authentication information.
4. The data detection system for physically isolated network according to claim 3, characterized in that: When the edge gateway executes the step of generating an encryption key based on the central gateway identifier and the identity authentication information, the execution steps of the edge gateway include: Performing hash processing based on the central gateway identifier to generate an initial key; Performing normalization and splicing processing on the edge gateway identifier of the edge gateway and the identity authentication information to generate a dynamic factor; Performing hash processing based on the dynamic factor to generate a dynamic key; The dynamic key and the initial key are subjected to XOR confusion processing to generate the encryption key.
5. The data detection system for physically isolated network according to claim 3, characterized in that: When the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution steps of the edge gateway include: Obtaining a network monitoring data acquisition request issued by the central gateway; Determining target network monitoring data from the network monitoring data based on the network monitoring data acquisition request, encrypting the target network monitoring data based on the encryption key, and generating encrypted data and a corresponding authentication tag; Based on the combination of the encrypted data and the authentication tag, combined encrypted network monitoring data is generated, and the combined encrypted network monitoring data is transmitted to the central gateway through the encrypted tunnel, so that the central gateway decrypts the combined encrypted network monitoring data and then transmits the target network monitoring data to the central monitoring server.
6. The data detection system for physically isolated network according to claim 5, characterized in that: When the edge gateway performs the encryption processing of the target network monitoring data based on the encryption key to generate encrypted data and a corresponding authentication tag, the execution steps include: Obtaining a nonlinear mapping table and generating a dislocation processing identifier; Based on the nonlinear mapping table, nonlinearly replace the target network monitoring data to generate nonlinear network monitoring data; Based on the dislocation processing identifier and the encryption key, performing dislocation encryption processing on the nonlinear network monitoring data to obtain the encrypted data; The authentication tag is generated based on the mapping table identifier of the nonlinear mapping table and the misalignment processing identifier.
7. The data detection system for a physically isolated network according to claim 6, characterized in that: The dislocation processing identifier includes a row shift identifier and a column mixing identifier. When the edge gateway performs the dislocation encryption processing on the nonlinear network monitoring data based on the dislocation processing identifier and the encryption key to obtain the encrypted data, the execution steps include: Selecting target row data from the nonlinear network monitoring data based on the row shift identifier to perform row shift to obtain first shift data; Acquire a mixing matrix corresponding to the column mixing identifier, select target column data from the first shifted data based on the column mixing identifier, and perform a matrix operation on the target column data and the mixing matrix to obtain second shifted data; The second shifted data is XOR-ed with the encryption key to obtain the encrypted data.
8. The data detection system for physically isolated network according to claim 5, characterized in that: When the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution steps of the central monitoring server include: Sending a network monitoring data acquisition request to the central gateway; Obtain target network monitoring data sent by the central gateway according to the network monitoring data acquisition request.
9. The data detection system for physically isolated network according to claim 8, characterized in that: When the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each of the network groups, the execution steps of the central gateway include: Receiving the network monitoring data acquisition request sent by the central monitoring server; Sending a central gateway identifier and the network monitoring data acquisition request to the edge gateway through the encrypted tunnel; Obtaining the combined encrypted network monitoring data sent by the edge gateway according to the network monitoring data acquisition request; Decoding the encrypted data in the combined encrypted network monitoring data based on the authentication tag in the combined encrypted network monitoring data to obtain the target network monitoring data corresponding to the network monitoring data acquisition request; The target network monitoring data is sent to the central monitoring server.
10. The data detection system for physically isolated network according to claim 1, characterized in that: When the data collector collects the network monitoring data of the plurality of network devices in the corresponding network group in real time, the steps include: When the current moment reaches a preset acquisition period, determining at least one target data type corresponding to the preset acquisition period; Collecting real-time type data corresponding to all the target data types from the multiple network devices in the network group; The network monitoring data is obtained based on all the real-time type data.
11. The data detection system for physically isolated network according to claim 1, characterized in that: After the central monitoring server reads the network monitoring data in the associated storage server from the edge gateway of each network group, the central monitoring server further performs the following steps: Integrate and process all the network monitoring data to obtain integrated network monitoring data; The integrated network monitoring data is aggregated and analyzed to obtain analysis and processing data, and the analysis and processing data is displayed in a graphical form.
Citation Information
Patent Citations
Resource access method and system under condition of network range scene isolation
CN116566749A
VPN tunnel connection method and device, central gateway, edge gateway and system
CN116633721A
Data processing method and device, equipment and storage medium
CN116743662A
Multi-network range collaborative data transmission method, device, equipment and medium
CN117811840A
Communication method and device, edge gateway and storage medium
CN118574090A