Full-link network communication encryption method and device

By introducing the design of a cryptographic server and an encryption and decryption module in network communication, the problem of difficulty in realizing full-link network communication in the prior art is solved, and a simple key issuance and communication process is realized, which improves communication security and efficiency.

CN120017382APending Publication Date: 2025-05-16THREE GORGES JINSHAJIANG CHUANYUN HYDROPOWER DEV CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510180032.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-19
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The prior art is difficult to realize full-link network communication encryption, especially in ordinary service TCP and UDP communications, and there are problems such as complex configuration, long negotiation process, and low communication efficiency based on IPSEC communication encryption.

Method used

A method and device for encrypting communications of full-link networks is designed, including a password server, an encryption and decryption control module and an encryption and decryption module. The encryption and decryption control module is deployed in the Linux operating system user space of each host, responsible for IP address registration and private key application, and the encryption and decryption module is deployed in the Linux kernel to realize the encryption and decryption of communication data.

Benefits of technology

It realizes the encryption protection of IP packets based on link communication in the local network, simplifies the key issuance and communication process, avoids additional steps such as key negotiation and tunnel establishment. The overall solution is simple to maintain and flexible to deploy, and realizes the effects of local encrypted communication and external normal communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017382A_ABST
    Figure CN120017382A_ABST
Patent Text Reader

Abstract

The invention discloses a full-link network communication encryption method and device, and relates to the field of computer network communication, and the encryption device comprises a password server which provides IP registration and private key issuing functions; the encryption and decryption control module is connected with the password server, performs IP address registration and applies for a private key; the encryption and decryption module communicates with the encryption and decryption control module and can execute encryption and decryption operations of communication data; the invention further provides an encryption method. According to the invention, the IP message encryption protection effect based on link communication in the local network can be realized, the method has a simple key issuing process, a simple communication process, no additional steps such as key negotiation, tunnel establishment and the like, the whole scheme is simple to maintain and flexible to deploy, and the effects of local encryption communication and external normal communication are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network communications, and in particular to a method and device for encrypting full-link network communications. Background Art

[0002] The statements in this section merely provide background information related to the present disclosure and may not constitute prior art.

[0003] In the field of computer network communications, communication encryption has become an important means of information security protection. In the requirements for critical infrastructure network security protection, communication encryption is one of the important compliance items, which can protect communication data from leakage, data from destruction, and network threats such as man-in-the-middle attacks.

[0004] In the communication model based on full-link encryption, it is generally necessary to set up a password server to complete the creation and distribution of secret keys for each host, set up communication encryption and decryption hardware and software components for each host, and negotiate the communication key of each host. At present, general communication encryption is implemented based on each business, such as PKI-based TLS negotiation communication for WEB access, which is difficult to encrypt and protect TCP and UDP communications for ordinary businesses; IPSEC-based communication encryption is limited to point-to-point tunnel communication, and there are problems such as complex configuration, long negotiation process, and low communication efficiency. It is difficult to achieve the communication encryption effect based on the full link. Communication encryption based on the full link can achieve the protection effect of data communication in the whole network. Summary of the invention

[0005] The purpose of the present invention is to provide a method and device for full-link network communication encryption to solve the problems existing in the prior art.

[0006] The technical solution of the present invention is as follows:

[0007] A device for full-link network communication encryption, comprising:

[0008] Password server, providing IP registration and private key distribution functions;

[0009] The encryption and decryption control module is connected to the password server to register the IP address and apply for a private key;

[0010] The encryption and decryption module communicates with the encryption and decryption control module and can perform encryption and decryption operations of communication data.

[0011] Furthermore, the encryption and decryption control module is deployed in the user space of the Linux operating system of each host; the encryption and decryption module is deployed in the Linux kernel.

[0012] Furthermore, the IP address registration and application for a private key include:

[0013] The encryption and decryption control module uses the password server IP address to encrypt the registration request message, generates a registration request message, and sends it to the password server; the registration request message content includes a random number, a timestamp, a random symmetric key, and a private key application IP address;

[0014] The cryptographic server uses its own private key to decrypt, extract the content of the registration request message, and generates a corresponding private key based on the private key application IP address; the cryptographic server uses the random symmetric key in the registration request message to encrypt the reply message, generate a reply message, and send it to the encryption and decryption control module; the reply message content includes: user private key, random number and timestamp;

[0015] The encryption and decryption control module uses a random symmetric key to decrypt, extracts the reply message content, verifies the correctness of the random number, extracts the private key, and sends it down for storage.

[0016] Furthermore, the communication process between hosts is as follows:

[0017] Host 1 communicates with host 2, with host 1 as the source address and host 2 as the destination address;

[0018] If the query source address and destination address are both within the full-link communication encryption address range, the IP address of host 2 is used as the public key to encrypt the communication message and generate a message to send to host 2;

[0019] Host 2 receives the message, extracts the source address and destination address of the message, and finds that both the source address and the destination address are within the full-link communication encryption address range, then uses its private key to decrypt the message; the decrypted message is sent to the protocol stack for further processing.

[0020] Furthermore, when determining whether the source address and the destination address are within the full-link communication encryption address range, a hash cache or cache list is used for accelerated processing.

[0021] Furthermore, the encryption and decryption module is released in the form of a Linux kernel module, based on a netfilter framework, to achieve dynamic loading and unloading of functions; in the netfilter framework, on the two nodes of IP_LOCAL_INPUT and IP_LOCAL_OUT, the processing HOOK of the encryption and decryption module is mounted to achieve encryption and decryption functions.

[0022] Furthermore, the cryptographic server has a fixed IP address and service port.

[0023] The present invention also proposes a method for encrypting full-link network communications, based on the above-mentioned device for encrypting full-link network communications, comprising:

[0024] Step S1: Each host initiates IP address registration to the password server and applies for a private key;

[0025] Step S2: Hosts communicate with each other based on the private key.

[0026] Furthermore, the step S1 comprises:

[0027] Step S11: The encryption and decryption control module encrypts the registration request message using the password server IP address, generates a registration request message, and sends it to the password server; the registration request message includes a random number, a timestamp, a random symmetric key, and a private key application IP address;

[0028] Step S12: The cryptographic server uses its own private key to decrypt, extract the content of the registration request message, and generates a corresponding private key according to the private key application IP address; the cryptographic server uses the random symmetric key in the registration request message to encrypt the reply message, generate a reply message, and send it to the encryption and decryption control module; the reply message content includes: user private key, random number and timestamp;

[0029] Step S13: The encryption and decryption control module decrypts with a random symmetric key, extracts the reply message content, verifies the correctness of the random number, extracts the private key, and sends it down for storage.

[0030] Furthermore, the step S2 comprises:

[0031] Step S21: Host 1 communicates with host 2, where host 1 is used as the source address and host 2 is used as the destination address;

[0032] Step S22: If the query source address and the destination address are both within the full-link communication encryption address range, the IP address of host 2 is used as the public key to encrypt the communication message, generate a message and send it to host 2;

[0033] Step S23: Host 2 receives the message, extracts the source address and destination address of the message, and finds that both the source address and the destination address are within the full-link communication encryption address range, then uses its private key to decrypt; and sends the decrypted message to the protocol stack for further processing.

[0034] Compared with the prior art, the present invention has the following beneficial effects:

[0035] The present invention can achieve the IP message encryption protection effect based on link communication in the local network, has a simple key issuance process, a simple communication process, no additional steps such as key negotiation and tunnel establishment, and the overall solution is simple to maintain and flexible to deploy, achieving the effect of local encrypted communication and external normal communication. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1A device communication architecture with full-link network communication encryption;

[0037] Figure 2 Flowchart for IP address registration and private key application;

[0038] Figure 3 It is the communication flow chart between each host;

[0039] Figure 4 This is the workflow diagram of the encryption and decryption module. DETAILED DESCRIPTION

[0040] It should be noted that relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0041] The features and performance of the present invention are further described in detail below in conjunction with the embodiments.

[0042] Embodiment 1

[0043] This embodiment transparently encrypts and decrypts network communications by deploying a general encryption and decryption component in the operating system. Specifically, the SM9 identity encryption method is adopted to assign a fixed IP address as an identity to each host. When each host is initialized, it applies to the password server for the private key corresponding to its identity, and its IP address is the public key. Through a specific registration and private key application and issuance protocol, each host initializes the password by applying to the password server for local storage of the private key. When communicating with other hosts, the other party's IP address is used as the public key to implement public key encryption, without key negotiation and exchange process; the target communication host receives the ciphertext and uses its private key to decrypt it, achieving the effect of one machine, one key, and fast communication.

[0044] It should be noted that in a full-link encrypted communication network, it is necessary to consider the communication between the host and the non-encrypted machine on the external network. Therefore, the encrypted communication range of the local network is specified by configuring the software parameters. Communication with hosts outside the range is not encrypted. When the host is initialized, a customized protocol is used to issue the private key when applying for the private key.

[0045] For details, please refer to Figure 1, a device for full-link network communication encryption, comprising:

[0046] The password server (i.e. the password machine in the figure) provides IP registration and private key distribution functions; it should be noted that the password server is an independent server device;

[0047] The encryption and decryption control module is connected to the password server to register the IP address and apply for a private key. It should be noted that the encryption and decryption control module is deployed in the user space of each host Linux operating system and is a program used to perform encryption and decryption module initialization, parameter configuration, key application and other tasks;

[0048] The encryption and decryption module communicates with the encryption and decryption control module and is capable of performing encryption and decryption operations on communication data; it should be noted that the encryption and decryption module is deployed in the Linux kernel, controls and participates in encryption and decryption communication tasks, and implements filtering, encryption and decryption functions on messages.

[0049] The deployment form of a full-link network communication encryption device proposed in this embodiment is as follows:

[0050] 1. The password server is deployed throughout the network. The password server has a fixed IP and service port, and provides IP registration and private key distribution functions;

[0051] 2. In each host operating system, deploy a general encryption and decryption component. This component is deployed in the Linux kernel. When the network card sends and receives messages, they are first processed and filtered by this kernel module;

[0052] 3. In each host operating system, deploy an encryption and decryption control module to implement parameter configuration, module initialization, private key application and other functions;

[0053] 4. Configure parameters for the encryption and decryption system, such as the IP address range for encrypted communication of the entire network link and the list of non-encrypted exception addresses. The user-mode encryption and decryption control module sends the parameters to the kernel encryption and decryption module, turns on the encryption and decryption function, and the encryption and decryption control module registers the IP address and applies for a private key;

[0054] 5. For network communication between nodes, public key encryption is performed using the other party's IP address as the public key. The other party's communication encryption module receives the message and uses the private key to decrypt it.

[0055] In this embodiment, specifically, Figure 2 As shown, the IP address is registered and a private key is applied for, including:

[0056] The encryption and decryption control module uses the password server IP address to encrypt the registration request message, generates a registration request message, and sends it to the password server; the registration request message content includes a random number, a timestamp, a random symmetric key, and a private key application IP address;

[0057] The cryptographic server uses its own private key to decrypt, extract the content of the registration request message, and generates a corresponding private key based on the private key application IP address; the cryptographic server uses the random symmetric key in the registration request message to encrypt the reply message, generate a reply message, and send it to the encryption and decryption control module; the reply message content includes: user private key, random number and timestamp;

[0058] The encryption and decryption control module uses a random symmetric key to decrypt, extracts the reply message content, verifies the correctness of the random number, extracts the private key, and sends it down for storage.

[0059] In this embodiment, specifically, Figure 3 As shown in the figure, the communication process between hosts is as follows:

[0060] Host 1 communicates with host 2, with host 1 as the source address and host 2 as the destination address;

[0061] If the query source address and destination address are both within the full-link communication encryption address range, the IP address of host 2 is used as the public key to encrypt the communication message and generate a message to send to host 2;

[0062] Host 2 receives the message, extracts the source address and destination address of the message, and finds that both the source address and the destination address are within the full-link communication encryption address range, then uses its private key to decrypt the message; the decrypted message is sent to the protocol stack for further processing.

[0063] In this embodiment, specifically, when determining whether the source address and the destination address are within the full-link communication encryption address range, a hash cache or cache list is used for accelerated processing.

[0064] In this embodiment, it should be noted that in the workflow of the encryption and decryption module, it is necessary to determine whether the communication partner is within the full link encryption address range and whether the communication protocol needs to be encrypted. The workflow is as follows: Figure 4 shown.

[0065] In this embodiment, the encryption and decryption module is released in the form of a Linux kernel module, based on the netfilter framework, to achieve dynamic loading and unloading of functions; in the netfilter framework, the encryption and decryption module processing HOOK is mounted on the two nodes IP_LOCAL_INPUT and IP_LOCAL_OUT to achieve encryption and decryption functions. The deployment location of the encryption and decryption module in linxu is shown in the red part of the following figure.

[0066] Embodiment 2

[0067] Embodiment 2 Based on the device for encrypting full-link network communication in Embodiment 1, a method for encrypting full-link network communication is also proposed, which specifically includes the following steps:

[0068] Step S1: Each host initiates IP address registration to the password server and applies for a private key;

[0069] Step S2: Hosts communicate with each other based on the private key.

[0070] In this embodiment, specifically, step S1 includes:

[0071] Step S11: The encryption and decryption control module encrypts the registration request message using the password server IP address, generates a registration request message, and sends it to the password server; the registration request message includes a random number, a timestamp, a random symmetric key, and a private key application IP address;

[0072] Step S12: The cryptographic server uses its own private key to decrypt, extract the content of the registration request message, and generates a corresponding private key according to the private key application IP address; the cryptographic server uses the random symmetric key in the registration request message to encrypt the reply message, generate a reply message, and send it to the encryption and decryption control module; the reply message content includes: user private key, random number and timestamp;

[0073] Step S13: The encryption and decryption control module decrypts with a random symmetric key, extracts the reply message content, verifies the correctness of the random number, extracts the private key, and sends it down for storage.

[0074] In this embodiment, specifically, step S2 includes:

[0075] Step S21: Host 1 communicates with host 2, where host 1 is used as the source address and host 2 is used as the destination address;

[0076] Step S22: If the query source address and the destination address are both within the full-link communication encryption address range, the IP address of host 2 is used as the public key to encrypt the communication message, generate a message and send it to host 2;

[0077] Step S23: Host 2 receives the message, extracts the source address and destination address of the message, and finds that both the source address and the destination address are within the full-link communication encryption address range, then uses its private key to decrypt; and sends the decrypted message to the protocol stack for further processing.

[0078] The above-mentioned embodiments only express the specific implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the protection scope of the present application. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the technical solution concept of the present application, and these all belong to the protection scope of the present application.

[0079] This background section is provided to generally present the context of the invention, and the work of the presently named inventors, the work to the extent described in this background section, and aspects of this section that did not constitute prior art at the time of application are neither explicitly nor implicitly admitted to be prior art to the present invention.

Claims

1. A device for encrypting full-link network communications, characterized in that: include: Password server, providing IP registration and private key distribution functions; The encryption and decryption control module is connected to the password server to register the IP address and apply for a private key; The encryption and decryption module communicates with the encryption and decryption control module and can perform encryption and decryption operations on communication data.

2. A device for full-link network communication encryption according to claim 1, characterized in that: The encryption and decryption control module is deployed in the user space of the Linux operating system of each host; the encryption and decryption module is deployed in the Linux kernel.

3. A device for full-link network communication encryption according to claim 1, characterized in that: The IP address registration and application for a private key include: The encryption and decryption control module uses the password server IP address to encrypt the registration request message, generates a registration request message, and sends it to the password server; the registration request message content includes a random number, a timestamp, a random symmetric key, and a private key application IP address; The cryptographic server uses its own private key to decrypt, extract the content of the registration request message, and generates a corresponding private key based on the private key application IP address; the cryptographic server uses the random symmetric key in the registration request message to encrypt the reply message, generate a reply message, and send it to the encryption and decryption control module; the reply message content includes: user private key, random number and timestamp; The encryption and decryption control module uses a random symmetric key to decrypt, extract the reply message content, verify the correctness of the random number, extract the private key, and send it down for storage.

4. A device for full-link network communication encryption according to claim 3, characterized in that: The communication process between hosts is as follows: Host 1 communicates with host 2, with host 1 as the source address and host 2 as the destination address; If the query source address and destination address are both within the full-link communication encryption address range, the IP address of host 2 is used as the public key to encrypt the communication message and generate a message to send to host 2; Host 2 receives the message, extracts the source address and destination address of the message, and finds that both the source address and the destination address are within the full-link communication encryption address range, and then uses its private key to decrypt; Send the decrypted message to the protocol stack for further processing.

5. A device for full-link network communication encryption according to claim 4, characterized in that: When determining whether the source address and the destination address are within the full-link communication encryption address range, a hash cache or cache list is used for accelerated processing.

6. A device for full-link network communication encryption according to claim 2, characterized in that: The encryption and decryption module is released in the form of a Linux kernel module and is based on a netfilter framework to achieve dynamic loading and unloading of functions. In the netfilter framework, the processing HOOK of the encryption and decryption module is mounted on the two nodes IP_LOCAL_INPUT and IP_LOCAL_OUT to achieve encryption and decryption functions.

7. A device for full-link network communication encryption according to claim 1, characterized in that: The password server has a fixed IP address and service port.

8. A method for encrypting full-link network communications, characterized in that: A device for full-link network communication encryption based on any one of claims 1 to 7, comprising: Step S1: Each host initiates IP address registration to the password server and applies for a private key; Step S2: Hosts communicate with each other based on the private key.

9. A method for encrypting full-link network communications according to claim 8, characterized in that: The step S1 comprises: Step S11: The encryption and decryption control module encrypts the registration request message using the password server IP address, generates a registration request message, and sends it to the password server; the registration request message includes a random number, a timestamp, a random symmetric key, and a private key application IP address; Step S12: The cryptographic server uses its own private key to decrypt, extract the content of the registration request message, and generates a corresponding private key according to the private key application IP address; the cryptographic server uses the random symmetric key in the registration request message to encrypt the reply message, generate a reply message, and send it to the encryption and decryption control module; the reply message content includes: user private key, random number and timestamp; Step S13: The encryption and decryption control module decrypts with a random symmetric key, extracts the reply message content, verifies the correctness of the random number, extracts the private key, and sends it down for storage.

10. A method for encrypting full-link network communications according to claim 9, characterized in that: The step S2 comprises: Step S21: Host 1 communicates with host 2, where host 1 is used as the source address and host 2 is used as the destination address; Step S22: If the query source address and the destination address are both within the full-link communication encryption address range, the IP address of host 2 is used as the public key to encrypt the communication message, generate a message and send it to host 2; Step S23: Host 2 receives the message, extracts the source address and destination address of the message, and finds that both the source address and the destination address are within the full-link communication encryption address range, then uses its private key to decrypt; and sends the decrypted message to the protocol stack for further processing.