Transparent encryption method and device, transparent decryption method and device, electronic equipment and storage medium

By using the bypass technology of the kernel protocol stack and the encryption and decryption configuration table in the railway signal security communication protocol, the data link layer is transparently encrypted and decrypted, which solves the problem of insufficient confidentiality of data transmission in the existing protocol and realizes the security and flexibility of data transmission.

CN120017387APending Publication Date: 2025-05-16CRSC RESEARCH & DESIGN INSTITUTE GROUP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510197658.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing railway signal security communication protocol does not encrypt the transmitted data, resulting in insufficient confidentiality of data transmission. Attackers can intercept plain text data to eavesdrop on sensitive data transmitted in the network, threatening the secure operation of the signal security data network.

Method used

The kernel protocol stack bypass technology and encryption and decryption configuration table are used to determine the encryption and decryption of packets at the data link layer, without any business changes and are transparent to services. The specific implementation includes using the first network card and the second network card in the gateway to receive and send messages, and encrypt and decrypt the messages through the encryption and decryption module, and generating an encrypted and decrypted session key using five-tuple information and derived key.

Benefits of technology

The confidentiality of data transmission is achieved, and the security of data is ensured through encryption and decryption processing is not required to make large-scale modifications to existing network equipment, and it has flexibility and high availability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017387A_ABST
    Figure CN120017387A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of password application, and provides a transparent encryption method and device, a transparent decryption method and device, electronic equipment and a storage medium, and the method comprises the steps that a second network card directly submits a received message to a data encryption and decryption module through a data link layer by using a bypass technology of a kernel protocol stack; the module extracts quintuple information in the message, matches the quintuple information with information in the encryption and decryption configuration table, encrypts the message if the quintuple information is matched with the information in the encryption and decryption configuration table and needs to be encrypted, and sends the encrypted message to a first network card; if matching is carried out and encryption is not needed, or if matching is not carried out, directly forwarding to the first network card; the encryption and decryption configuration table comprises a corresponding relation between quintuple information and whether encryption is needed or not; and the first network card sends the message. Data encryption and decryption or plaintext transparent transmission are realized in a self-adaptive manner based on session quintuple information in an encryption process by adopting a bypass technology of a kernel protocol stack, and the flexibility is very high; and the security in the data encryption and decryption transmission process is ensured to the greatest extent.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cryptographic application technology, and in particular relates to a transparent encryption method, a decryption method, a device, an electronic device and a storage medium. Background Art

[0002] The high-speed railway train control system is the brain and central nervous system for the safe, stable and orderly operation of high-speed railway trains. The high-speed railway train control system network adopts a double-ring network redundant architecture mode, which ensures the efficient, stable, safe and orderly transmission of data in the high-speed railway train control network. In addition, in the high-speed railway train control system, most of the private RSSP-I and RSSP-II proprietary railway signal safety communication protocols are used for data transmission. This protocol uses mechanisms such as serial number, timestamp, timeout protection, source identification, feedback message, double message, etc. to prevent data duplication, loss, insertion, wrong sequence, wrong code, delay and other dangerous situations, effectively ensuring the security, stability and reliability of data transmission in the high-speed railway train control system, and realizing efficient, stable and safe data flow in the double-ring network of the high-speed railway train control system.

[0003] However, in the existing railway signal security communication protocol, the transmitted data is not encrypted and the data is transmitted in plain text. Although the integrity and correctness of the data transmission can be guaranteed through a double verification mechanism, the confidentiality of the data transmission cannot be guaranteed. As a result, attackers can intercept the plain text data in the railway signal security data network and then eavesdrop on the sensitive data transmitted in the network through eavesdropping and other means. By analyzing these sensitive data, they can obtain information such as the core asset status and lines of the train control system, thereby threatening the safe operation of the signal security data network.

[0004] Although it is possible to deploy encryption gateways in the signal security data network to achieve the confidentiality of data transmission in the signal security data network, most traditional gateways use a three-layer routing mode, which encrypts and decrypts upstream and downstream data by connecting them in series in the signal security data network. Although this achieves the confidentiality of data transmission, this method has the following two disadvantages. On the one hand, the three-layer mode requires large-scale modifications to the configuration of existing network equipment, which modifies the original transmission mode of the network and lacks flexibility. On the other hand, gateway devices need to be paired and connected in series in the network. Once a failure occurs, the entire network will be paralyzed.

[0005] In view of this, it is necessary to propose a transparent encryption method, a decryption method, a device, an electronic device and a storage medium. Summary of the invention

[0006] To solve the above problems, the present invention provides a transparent encryption method, a decryption method, an apparatus, an electronic device and a storage medium, which adopt the bypass technology of the kernel protocol stack and use the encryption and decryption configuration table to encrypt and decrypt the message at the data link layer without the need for business changes and is transparent to the business.

[0007] In a first aspect, an adaptive transparent encryption method is provided, which is applied in a gateway including a first network card NIC1, an encryption and decryption module, and a second network card NIC2, including:

[0008] The second network card NIC2 receives the message containing plaintext data, and uses the bypass technology of the kernel protocol stack to directly submit the message to the data encryption and decryption module via the data link layer;

[0009] The data encryption and decryption module extracts the five-tuple information in the message, matches the five-tuple information with the information in the encryption and decryption configuration table, and if it matches and encryption is required, encrypts the message and sends the encrypted message to the first network card NIC1; if it matches and encryption is not required, or if it does not match, it is directly forwarded to the first network card NIC1; wherein the encryption and decryption configuration table contains the corresponding relationship between the five-tuple information and whether encryption is required;

[0010] The first network card NIC1 sends the message from the data encryption and decryption module.

[0011] Furthermore, the encryption and decryption configuration table also includes a correspondence between the five-tuple information and the encryption and decryption algorithms;

[0012] The data encryption module encrypts the message, including:

[0013] The data encryption and decryption module generates an encryption and decryption session key using the extracted five-tuple information and the derived key. The derived key is obtained by deriving and calculating the smart key using the derived key algorithm and the set rules during the startup process of each gateway.

[0014] The data encryption and decryption module encrypts the message by calling the encryption algorithm corresponding to the extracted five-tuple information based on the encryption and decryption session key.

[0015] Furthermore, the data encryption and decryption module generates an encryption and decryption session key using the extracted five-tuple information and the derived key, including:

[0016] The data encryption and decryption module uses the five-tuple information of the message as the input of the national secret SM3 hash algorithm to generate a salt value; uses the derived key as the input of the national secret SM3 hash algorithm to generate a 256-bit hash value; uses the 256-bit hash value, salt value, the set number of iterations, the size of the data block in the message and the set length of the generated key as the input of the key derivation algorithm scrypt to generate an encryption and decryption session key.

[0017] In a second aspect, an adaptive transparent decryption method is provided, which is applied in a gateway including a first network card NIC1, an encryption and decryption module, and a second network card NIC2, including:

[0018] The first network card NIC1 receives the message containing the ciphertext data, and directly submits the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack;

[0019] The data encryption and decryption module extracts the five-tuple information in the message, matches the five-tuple information with the information in the encryption and decryption configuration table, and if it matches and decryption is required, decrypts the message and sends the decrypted message to the second network card NIC2; if it matches and decryption is not required, or if it does not match, it is directly forwarded to the second network card NIC2; wherein the encryption and decryption configuration table contains the corresponding relationship between the five-tuple information and whether encryption is required;

[0020] The second network card NIC2 sends the message from the data encryption and decryption module.

[0021] Furthermore, the encryption and decryption configuration table also includes a correspondence between the five-tuple information and the encryption and decryption algorithms;

[0022] The data encryption module decrypts the message, including:

[0023] The data encryption and decryption module generates an encryption and decryption session key using the extracted five-tuple information and the derived key. The derived key is obtained by deriving and calculating the smart key using the derived key algorithm and the set rules during the startup process of each gateway.

[0024] The data encryption and decryption module calls the decryption algorithm corresponding to the extracted five-tuple information to decrypt the message based on the encryption and decryption session key.

[0025] Furthermore, the data encryption and decryption module generates an encryption and decryption session key using the extracted five-tuple information and the derived key, including:

[0026] The data encryption and decryption module uses the five-tuple information of the message as the input of the national secret SM3 hash algorithm to generate a salt value; uses the derived key as the input of the national secret SM3 hash algorithm to generate a 256-bit hash value; uses the 256-bit hash value, salt value, the set number of iterations, the size of the data block and the set length of the generated key as the input of the key derivation algorithm scrypt to generate an encryption and decryption session key.

[0027] In a third aspect, an adaptive transparent encryption device is provided, comprising: a first network card NIC1, an encryption and decryption module, and a second network card NIC2; wherein:

[0028] The second network card NIC2 is used to receive the message containing plaintext data, and directly submit the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack;

[0029] A data encryption and decryption module, used for extracting quintuple information from a message, matching the quintuple information with information in an encryption and decryption configuration table, encrypting the message if it matches and encryption is required, and sending the encrypted message to the first network card NIC1; if it matches and encryption is not required, or if it does not match, directly forwarding it to the first network card NIC1; wherein the encryption and decryption configuration table contains a corresponding relationship between the quintuple information and whether encryption is required;

[0030] The first network card NIC1 is used to send messages from the data encryption and decryption module.

[0031] In a fourth aspect, an adaptive transparent decryption device is provided, comprising: a first network card NIC1, an encryption and decryption module, and a second network card NIC2; wherein:

[0032] The first network card NIC1 is used to receive the message containing the ciphertext data, and directly submit the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack;

[0033] A data encryption and decryption module, used to extract the five-tuple information in the message, match the five-tuple information with the information in the encryption and decryption configuration table, and if it matches and needs to be decrypted, decrypt the message and send the decrypted message to the second network card NIC2; if it matches and does not need to be decrypted, or does not match, directly forward it to the second network card NIC2; wherein the encryption and decryption configuration table contains the corresponding relationship between the five-tuple information and whether encryption is required;

[0034] The second network card NIC2 is used to send the message from the data encryption and decryption module.

[0035] In a fifth aspect, an electronic device is provided, comprising a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus;

[0036] Memory, used to store computer programs;

[0037] The processor is used to implement the steps of the above method when executing the program stored in the memory.

[0038] In a sixth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and the computer program implements the steps of the above method when executed by a processor.

[0039] Compared with the prior art, the present invention has the following advantages:

[0040] 1. Compared with the traditional encryption gateway, the solution of the embodiment of the present disclosure adopts the bypass technology of the kernel protocol stack to realize the transparent forwarding and encryption and decryption of the second layer of the message data received by the network card, without any modification to the service, and the encryption and decryption of the service data can be realized by directly connecting the gateway to the network;

[0041] 2. At the same time, based on the session five-tuple information during the encryption process, it can adaptively implement encryption and decryption of some data and plain text transmission of some data, which has strong flexibility;

[0042] 3. The encryption and decryption session keys used in the data encryption and decryption process are generated based on the five-tuple information. Different sessions have different encryption and decryption session keys, which maximizes the security of data encryption and decryption transmission.

[0043] Other features and advantages of the present disclosure will be described in the following description, and partly become apparent from the description, or be understood by implementing the present disclosure. The purpose and other advantages of the present disclosure can be realized and obtained by the structures pointed out in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0045] Figure 1 A schematic diagram of the hardware architecture of an adaptive transparent encryption and decryption gateway according to an embodiment of the present disclosure is shown;

[0046] Figure 2 A schematic diagram of message flow logic of an adaptive transparent encryption and decryption gateway encryption and decryption according to an embodiment of the present disclosure is shown;

[0047] Figure 3 A flow chart of an adaptive transparent encryption and decryption gateway encryption and decryption method according to an embodiment of the present disclosure is shown;

[0048] Figure 4 A plaintext data encryption flow chart according to an embodiment of the present disclosure is shown;

[0049] Figure 5 A plaintext data decryption flow chart according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solution and advantages of the embodiments of the present disclosure clearer, the technical solution in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.

[0051] Figure 1 A schematic diagram of the hardware architecture of an adaptive transparent encryption and decryption gateway applicable to rail transit according to an embodiment of the present disclosure is shown, wherein the schematic diagram of the hardware architecture shows a gateway 1 and a gateway 2;

[0052] The rail transit adaptive transparent encryption and decryption gateway is used in pairs in the network, and each gateway contains at least two business network cards (Network Interface Card, NIC): the first network card NIC1 and the second network card NIC2, where the first network card NIC1 network port only receives the ciphertext data transmitted in the north direction, and after being decrypted by the encryption and decryption module, it is transmitted to the second network card NIC2 network port, and the second network card NIC2 transmits the plaintext data to the business system for use; the second network card NIC2 network port only receives the plaintext data transmitted in the south direction, and after being encrypted by the encryption and decryption module, it is transmitted to the first network card NIC1 network port, and the first network card NIC1 transmits the ciphertext data to another gateway for decryption processing. That is, the first network card NIC1 ciphertext in and plaintext out, the second network card NIC2 plaintext in and ciphertext out.

[0053] The gateway is designed with a hardware-level bypass function, which can bypass the encryption and decryption processing module in time when the encryption and decryption module of the device fails, thus ensuring the continuity of message transmission.

[0054] Figure 2 The figure shows a schematic diagram of the flow logic of encryption and decryption messages of an adaptive transparent encryption and decryption gateway according to an embodiment of the present disclosure, which is applicable to rail transit. Figure 2 Two gateways NC1 and NC2 are drawn in the figure to realize data encryption and decryption transmission between device 1 and device 2.

[0055] like Figure 3 As shown in the flowchart of the adaptive transparent encryption and decryption method of the embodiment of the present disclosure, the process of transmitting plaintext data from device 1 to device 2 via gateway 1 and gateway 2 includes the following steps:

[0056] S101: After receiving a message containing plaintext data sent by device 1, the second network card NIC2 of gateway 1 transmits the message to the data encryption and decryption module of gateway 1 for processing;

[0057] S102: The data encryption and decryption module of gateway 1 extracts the five-tuple information of the message, and uses the five-tuple information to determine whether the message needs to be encrypted or decrypted. If the message does not need to be encrypted or decrypted, the message is directly forwarded; if encryption is required, the encryption key required for encryption and decryption of the message is generated based on the five-tuple information of the message and the derived key, and the message is encrypted;

[0058] It should be noted that the same smart key exists in the paired gateways. During the startup of the gateway, the smart key is derived using the derived key algorithm and the same rules to calculate the derived key on each gateway. The derived key is used as the reference key for message encryption and decryption. The smart key can be imported into the gateway via USB or other methods, and the derived key algorithm can be PBKDF2.

[0059] The above five-tuple information is: source IP address, destination IP address, protocol number, source port and destination port.

[0060] The S102 determines whether encryption and decryption are required, thereby realizing partial encryption and decryption transmission and partial plain text transmission for the business device.

[0061] S103: the data encryption and decryption module of gateway 1 transmits the message after encryption and decryption to the first network card NIC1 of gateway 1, and the first network card NIC1 of gateway 1 forwards the message to gateway 2;

[0062] S104: After the first network card NIC1 of gateway 2 receives the ciphertext data transmitted by gateway 1, it is directly forwarded by layer 2 to the data encryption and decryption module of gateway 2;

[0063] S105: The data encryption and decryption module of gateway 2 extracts the five-tuple information of the message, and determines whether the message needs to be encrypted or decrypted based on the five-tuple information. If the message does not need to be encrypted or decrypted, the message is directly forwarded; if decryption is required, the decryption key required for encryption and decryption of the message is generated based on the five-tuple information of the message and the derived key, and the message is decrypted;

[0064] In the above S102 and S105, in the paired gateway, an encryption and decryption configuration table with the same encryption and decryption will be entered or imported in advance according to the communication relationship between devices in the rail transit network. The encryption and decryption configuration table configures the information whether the data communication between the five-tuples that communicate with each other is encrypted and decrypted. If the five-tuple information extracted from the message matches the information in the encryption and decryption configuration table and encryption and decryption are required, the message is encrypted; if it does not match and encryption and decryption are not required, encryption is not required and it is forwarded directly.

[0065] S106: The data encryption and decryption module of gateway 2 transmits the encrypted and decrypted message to the second network card NIC2 of gateway 2, and the second network card NIC2 forwards the message to device 2.

[0066] The process of transmitting plaintext data from device 2 to device 1 via gateway 2 and gateway 1 is similar to S101 to S106 above. The data encryption and decryption module in the rail transit adaptive transparent encryption and decryption gateway can make a judgment on the encryption and decryption of the data message based on the five-tuple information of the message. If the message does not need to be encrypted or decrypted, the message is directly forwarded to the corresponding NIC card, and the corresponding NIC card forwards the message out; if the message needs to be encrypted or decrypted, the data encryption and decryption module calculates the encryption and decryption session key of the message based on the five-tuple information of the message by deriving the key, calls the corresponding encryption algorithm to perform encryption and decryption calculations on the message, and submits the encrypted and decrypted data to the corresponding NIC card, which forwards the message out.

[0067] The above-mentioned gateway supports the national secret algorithm, and the above-mentioned encryption algorithm is the national secret SM1 algorithm.

[0068] Figure 4 A plaintext data encryption flow chart according to an embodiment of the present disclosure is shown, comprising the following steps:

[0069] Step 301: The second network card NIC2 receives a message containing plaintext data;

[0070] Step 302: The second network card NIC2 uses the bypass technology of the kernel protocol stack to directly submit the message to the data encryption and decryption module via the second layer;

[0071] Here, the bypass technology of the kernel protocol stack is used to bypass the kernel protocol stack of the system, and the message can be directly submitted to the data encryption and decryption module through the data link layer.

[0072] Step 303: The data encryption and decryption module extracts the five-tuple information in the message;

[0073] Step 304: The data encryption and decryption module determines whether the message needs to be encrypted and decrypted; if so, execute step 305; if not, execute step 308;

[0074] Step 305: The data encryption and decryption module generates an encryption and decryption session key using the message five-tuple information and the derived key, and then executes step 306;

[0075] Specifically, the data encryption and decryption module uses the five-tuple information of the message as the input of the national secret SM3 hash algorithm to generate a salt value; uses the derived key as the input of the national secret SM3 hash algorithm to generate a 256-bit hash value; uses the 256-bit hash value, salt value, the set number of iterations, the size of the data block in the message and the set length of the generated key as the input of the scrypt key derivation algorithm to generate an encryption and decryption session key.

[0076] Password=SM3(Password1)

[0077] Salt = SM3 (IPTuple)

[0078] Key=scrypt(Password,Salt,N,R,Key_len)

[0079] Among them, Password is the hash value generated by the derived key using the national secret SM3 hash algorithm, Password is the derived key generated based on the derivation function, IPTuple is the five-tuple information of the extracted message, Key is the generated encryption and decryption session key, Salt is the hash value generated by the five-tuple information using the national secret SM3 hash algorithm; N is the number of algorithm iterations; R is the size of the data block during the algorithm calculation process, Key_len: the generated key length.

[0080] Since the same key and derived key generation rules are used in the paired gateways, the derived keys generated by the two gateways are guaranteed to be the same. The five-tuple information in the same session is also fixed, thereby ensuring that the encryption and decryption session keys generated by the two gateways based on the derived derived keys and five-tuple information are also the same, achieving consistency in the encryption and decryption session keys of the two gateways.

[0081] Step 306: Based on the encryption and decryption session key, call the corresponding encryption algorithm to encrypt the message, and then execute step 307;

[0082] The encryption and decryption configuration table also includes the corresponding relationship between the five-tuple information and the encryption and decryption algorithm;

[0083] The encryption algorithm here can be the SM1 national encryption algorithm.

[0084] Step 307: forward the encrypted message to the first network card NIC1, and then execute step 309;

[0085] Step 308: directly forward the message to the first network card NIC1, and then execute step 309;

[0086] Step 309: The first network card NIC1 receives the message and sends the message out.

[0087] During the initialization process of the adaptive link encryption gateway, the derived key used for device encryption and decryption will be generated based on the intelligent key in the device according to the corresponding algorithm. The derived key is used as the reference key for generating the encryption and decryption session key. When the data message arrives, the encryption and decryption session key of the message is generated by extracting the message five-tuple information and the derived key according to the encryption and decryption session key generation algorithm, and the message data is encrypted and decrypted, thereby ensuring that different five-tuple session messages have different encryption and decryption session keys, and maximizing the confidentiality of the communication data.

[0088] Figure 5 A plaintext data decryption flow chart according to an embodiment of the present disclosure is shown, comprising the following steps:

[0089] Step 401: The first network card NIC1 receives a message containing ciphertext data;

[0090] Step 402: The first network card NIC1 uses the bypass technology of the kernel protocol stack to directly submit the ciphertext data to the data encryption and decryption module via the second layer;

[0091] Step 403: The data encryption and decryption module extracts the five-tuple information in the message;

[0092] Step 404: The data encryption and decryption module determines whether the message needs to be encrypted and decrypted; if so, execute step 405; if not, execute step 408;

[0093] Step 405: The data encryption and decryption module generates an encryption and decryption session key using the message five-tuple information and the derived key, and then executes step 406;

[0094] Specifically, the data encryption and decryption module uses the five-tuple information of the message as the input of the national secret SM3 hash algorithm to generate a salt value; uses the derived key as the input of the national secret SM3 hash algorithm to generate a 256-bit hash value; uses the 256-bit hash value, salt value, set number of iterations, data block size and set length of the generated key as input of the scrypt key derivation algorithm to generate an encryption and decryption session key.

[0095] Password=SM3(Password1)

[0096] Salt = SM3 (IPTuple)

[0097] Key=scrypt(Password,Salt,N,R,Key_len)

[0098] Among them, Password is the hash value generated by the derived key using the national secret SM3 hash algorithm, Password is the derived key generated based on the derivation function, IPTuple is the five-tuple information of the extracted message, Key is the generated encryption and decryption session key, Salt is the hash value generated by the five-tuple information using the national secret SM3 hash algorithm; N is the number of algorithm iterations; R is the size of the data block during the algorithm calculation process, Key_len: the generated key length.

[0099] Step 406: Based on the encryption and decryption session key, call the corresponding decryption algorithm to decrypt the message, and then execute step 407;

[0100] The corresponding decryption algorithm here can be the SM1 national secret algorithm.

[0101] Step 407: forward the decrypted message to the second network card NIC2, and then execute step 409;

[0102] Step 408: directly forward the message to the second network card NIC2, and then execute step 409;

[0103] Step 409: The second network card NIC2 receives the message and sends the message out.

[0104] In the paired decryption gateways, a universal intelligent key and derived key, encryption and decryption session key generation algorithm is used. The algorithm ensures that the session keys generated based on the quintuple in the paired gateways are the same, thereby ensuring the consistency of the encryption and decryption process.

[0105] The solution of the disclosed embodiment is flexible and economical, and does not require the deployment of additional equipment. At the same time, the gateway directly generates encryption and decryption session keys for any five-tuple message, and there is no need to transmit the encryption and decryption session keys in the network. All is completed locally in the gateway, making the encryption and decryption session keys more secure and without transmission delay, and the encryption and decryption session keys can be obtained more quickly.

[0106] An adaptive transparent encryption device comprises: a first network card NIC1, an encryption and decryption module and a second network card NIC2; wherein:

[0107] The second network card NIC2 is used to receive the message containing plaintext data, and directly submit the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack;

[0108] A data encryption and decryption module, used for extracting quintuple information from a message, matching the quintuple information with information in an encryption and decryption configuration table, encrypting the message if it matches and encryption is required, and sending the encrypted message to the first network card NIC1; if it matches and encryption is not required, or if it does not match, directly forwarding it to the first network card NIC1; wherein the encryption and decryption configuration table contains a corresponding relationship between the quintuple information and whether encryption is required;

[0109] The first network card NIC1 is used to send messages from the data encryption and decryption module.

[0110] An adaptive transparent decryption device comprises: a first network card NIC1, an encryption and decryption module and a second network card NIC2; wherein:

[0111] The first network card NIC1 is used to receive the message containing the ciphertext data, and directly submit the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack;

[0112] A data encryption and decryption module, used to extract the five-tuple information in the message, match the five-tuple information with the information in the encryption and decryption configuration table, and if it matches and needs to be decrypted, decrypt the message and send the decrypted message to the second network card NIC2; if it matches and does not need to be decrypted, or does not match, directly forward it to the second network card NIC2; wherein the encryption and decryption configuration table contains the corresponding relationship between the five-tuple information and whether encryption is required;

[0113] The second network card NIC2 is used to send the message from the data encryption and decryption module.

[0114] Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.

Claims

1. An adaptive transparent encryption method, characterized in that: The invention is applied in a gateway including a first network card NIC1, an encryption and decryption module, and a second network card NIC2, including: The second network card NIC2 receives the message containing plaintext data, and uses the bypass technology of the kernel protocol stack to directly submit the message to the data encryption and decryption module via the data link layer; The data encryption and decryption module extracts the five-tuple information in the message, matches the five-tuple information with the information in the encryption and decryption configuration table, and if it matches and encryption is required, encrypts the message and sends the encrypted message to the first network card NIC1; if it matches and encryption is not required, or if it does not match, directly forwards the message to the first network card NIC1; wherein the encryption and decryption configuration table contains the corresponding relationship between the five-tuple information and whether encryption is required; The first network card NIC1 sends the message from the data encryption and decryption module.

2. The method according to claim 1, characterized in that The encryption and decryption configuration table also includes the corresponding relationship between the five-tuple information and the encryption and decryption algorithm; The data encryption module encrypts the message, including: The data encryption and decryption module generates an encryption and decryption session key using the extracted five-tuple information and the derived key. The derived key is obtained by deriving and calculating the smart key using the derived key algorithm and the set rules during the startup process of each gateway. The data encryption and decryption module encrypts the message by calling the encryption algorithm corresponding to the extracted five-tuple information based on the encryption and decryption session key.

3. The method according to claim 1, characterized in that The data encryption and decryption module uses the extracted five-tuple information and derived keys to generate encryption and decryption session keys, including: The data encryption and decryption module uses the five-tuple information of the message as the input of the national secret SM3 hash algorithm to generate a salt value; uses the derived key as the input of the national secret SM3 hash algorithm to generate a 256-bit hash value; uses the 256-bit hash value, salt value, the set number of iterations, the size of the data block in the message and the set length of the generated key as the input of the key derivation algorithm scrypt to generate an encryption and decryption session key.

4. An adaptive transparent decryption method, characterized in that: The invention is applied in a gateway including a first network card NIC1, an encryption and decryption module, and a second network card NIC2, including: The first network card NIC1 receives the message containing the ciphertext data, and directly submits the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack; The data encryption and decryption module extracts the five-tuple information in the message, matches the five-tuple information with the information in the encryption and decryption configuration table, and if it matches and decryption is required, decrypts the message and sends the decrypted message to the second network card NIC2; if it matches and decryption is not required, or if it does not match, it is directly forwarded to the second network card NIC2; wherein the encryption and decryption configuration table contains the corresponding relationship between the five-tuple information and whether encryption is required; The second network card NIC2 sends the message from the data encryption and decryption module.

5. The method according to claim 4, characterized in that The encryption and decryption configuration table also includes the corresponding relationship between the five-tuple information and the encryption and decryption algorithm; The data encryption module decrypts the message, including: The data encryption and decryption module generates an encryption and decryption session key using the extracted five-tuple information and the derived key. The derived key is obtained by deriving and calculating the smart key using the derived key algorithm and the set rules during the startup process of each gateway. The data encryption and decryption module calls the decryption algorithm corresponding to the extracted five-tuple information to decrypt the message based on the encryption and decryption session key.

6. The method according to claim 1, characterized in that The data encryption and decryption module uses the extracted five-tuple information and derived keys to generate encryption and decryption session keys, including: The data encryption and decryption module uses the five-tuple information of the message as the input of the national secret SM3 hash algorithm to generate a salt value; uses the derived key as the input of the national secret SM3 hash algorithm to generate a 256-bit hash value; uses the 256-bit hash value, salt value, the set number of iterations, the size of the data block and the set length of the generated key as the input of the key derivation algorithm scrypt to generate an encryption and decryption session key.

7. An adaptive transparent encryption device, characterized in that: include: A first network card NIC1, an encryption and decryption module, and a second network card NIC2; wherein: The second network card NIC2 is used to receive the message containing plaintext data, and directly submit the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack; A data encryption and decryption module, used for extracting quintuple information from a message, matching the quintuple information with information in an encryption and decryption configuration table, encrypting the message if it matches and encryption is required, and sending the encrypted message to the first network card NIC1; if it matches and encryption is not required, or if it does not match, directly forwarding the message to the first network card NIC1; wherein the encryption and decryption configuration table contains a corresponding relationship between the quintuple information and whether encryption is required; The first network card NIC1 is used to send messages from the data encryption and decryption module.

8. An adaptive transparent decryption device, characterized in that: include: A first network card NIC1, an encryption and decryption module, and a second network card NIC2; wherein: The first network card NIC1 is used to receive the message containing the ciphertext data, and directly submit the message to the data encryption and decryption module via the data link layer by using the bypass technology of the kernel protocol stack; A data encryption and decryption module, used to extract the five-tuple information in the message, match the five-tuple information with the information in the encryption and decryption configuration table, and if it matches and decryption is required, decrypt the message and send the decrypted message to the second network card NIC2; if it matches and decryption is not required, or if it does not match, directly forward the message to the second network card NIC2; wherein the encryption and decryption configuration table contains the corresponding relationship between the five-tuple information and whether encryption is required; The second network card NIC2 is used to send the message from the data encryption and decryption module.

9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory, used to store computer programs; A processor, for implementing the steps of any method described in claims 1-6 when executing a program stored in a memory.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of any one of the methods of claims 1-6 are implemented.