Message processing method, electronic equipment and storage medium
By adopting dynamic mask scrambling operations and real-time policy configuration methods in password devices, the weak problems of password devices in anti-network penetration attacks are solved, efficient filtering and encrypted transmission are achieved, and the resistance to network attacks is enhanced.
Patent Information
- Application Number
- CN202510195177.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-05-27
AI Technical Summary
Password devices are weak in resisting intranet penetration attacks and remote network penetration attacks, and are prone to resource exhaustion, service interruption or response delays due to receiving large or excessively long illegal messages.
Using a combination of dynamic mask scrambling operations and real-time policy configuration, network messages are filtered through the interface isolation unit, the dynamic mask pool configured by the main control unit scrambles legal messages, and the local mask pool of the cryptographic unit descrambles encrypted messages, ultimately realizing efficient filtering and encrypted transmission.
Effectively filter illegal messages entering the password device, reduce the risk of policy leakage, reduce the internal processing overhead and communication bandwidth of the password device to be invalid, enhance the resistance to network attacks, prevent service interruptions, and improve the system's service capabilities.
Smart Images

Figure CN120050090A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and particularly relates to a message processing method, an electronic device, and a storage medium. Background Art
[0002] The cryptographic devices deployed in the network environment usually focus on the cryptographic service capabilities of the local system, but are usually weak in aspects such as resisting internal network penetration attacks and remote network penetration attacks.
[0003] In the related art, as one of the important network attack means, the interface attack sends a large number of or extremely long illegal messages or defective messages to the cryptographic device through the network interface within a short time, abnormally occupying the processing resources of the cryptographic device, exhausting or causing errors in the storage resources and processing resources of the cryptographic device, resulting in the interruption of the cryptographic device service or response delay, and seriously affecting the system function. Summary of the Invention
[0004] In view of the above problems, this application provides a message processing method, an electronic device, and a storage medium to efficiently and flexibly filter illegal messages and reduce the invalid occupation of the internal processing overhead and communication bandwidth of the cryptographic device.
[0005] In a first aspect, an embodiment of this application provides a message processing method applied to a cryptographic device. The cryptographic device includes: an interface isolation unit, a main control unit, and a cryptographic unit. The interface isolation unit is connected to a network interface. The message processing method includes:
[0006] Receiving a network message sent by a user based on the network interface;
[0007] Performing filtering processing on the network message based on the interface isolation unit to obtain a legal network message;
[0008] Performing dynamic mask scrambling processing on the legal network message based on a dynamic mask pool configured by the main control unit to obtain an encrypted network message;
[0009] Performing mask descrambling operation on the encrypted network message based on a local mask pool of the cryptographic unit to obtain a decrypted network message;
[0010] Sending the decrypted network message to the user based on the network interface.
[0011] In some embodiments, the filtering processing includes preliminary filtering processing and custom filtering processing. The performing filtering processing on the network message based on the interface isolation unit to obtain a legal network message includes:
[0012] Performing preliminary filtering processing on the network message based on the interface isolation unit to obtain a first network message;
[0013] Configure a filtering policy for the master control unit based on user requirements, and perform custom filtering processing on the first network packet according to the filtering policy to obtain a legal network packet.
[0014] In some embodiments, the packet processing method further includes:
[0015] Perform dynamic mask scrambling operation protection on the filtering policy.
[0016] In some embodiments, the master control unit is further connected to a noise source chip. The performing dynamic mask scrambling operation protection on the filtering policy includes:
[0017] Perform an exclusive OR operation on the two noise source chips and then use randomness detection to generate a random mask value, where the randomness detection includes: frequency test, serial test, poker test, run test, and autocorrelation test;
[0018] Send the random mask value along with the filtering policy to protect the filtering policy.
[0019] In some embodiments, the packet processing method further includes:
[0020] Send an application request for a dynamic mask pool to the master control unit;
[0021] Based on the application request, issue a dynamic mask pool to the interface isolation unit and the cipher unit.
[0022] In some embodiments, the interface isolation unit includes: a first local mask pool. The performing dynamic mask scrambling processing on the legal network packet based on the dynamic mask pool configured by the master control unit to obtain an encrypted network packet includes:
[0023] Obtain a first mask value based on the first local mask pool;
[0024] Perform dynamic mask scrambling processing on the legal network packet based on the first mask value to obtain an encrypted network packet.
[0025] In some embodiments, the cipher unit includes: a second local mask pool. The performing mask descrambling operation on the encrypted network packet based on the local mask pool of the cipher unit to obtain a decrypted network packet includes:
[0026] Obtain a corresponding second mask value from the local mask pool based on the mask group number in the internal protocol of the cipher unit;
[0027] Perform mask descrambling operation on the data area of the encrypted network packet based on the second mask value.
[0028] In some embodiments, performing an exclusive OR operation on the two noise source chips and then performing a randomness detection to generate a random mask value includes:
[0029] Reading first detection data of one of the noise source chips and reading second detection data of the other noise source chip;
[0030] Performing a data exclusive OR operation based on the first detection data and the second detection data to obtain a random mask value;
[0031] In the case where the random mask value does not meet any item in the randomness detection, an error alarm is performed.
[0032] In a second aspect, an embodiment of the present application provides an electronic device, including a memory and a processor. A program code that can run on the processor is stored on the memory. When the program code is executed by the processor, the message processing method introduced in any implementation manner of the first aspect is implemented.
[0033] In a third aspect, an embodiment of the present application provides a computer storage medium. The computer storage medium stores one or more programs, and the one or more programs can be executed by the electronic device introduced in the third aspect to implement the message processing method introduced in any implementation manner of the first aspect.
[0034] A message processing method, an electronic device, and a storage medium provided by an embodiment of the present application are applied to a cryptographic device. The cryptographic device includes: an interface isolation unit, a main control unit, and a cryptographic unit. The interface isolation unit is connected to a network interface. By receiving a network message sent by a user based on the network interface, filtering the network message based on the interface isolation unit to obtain a legal network message, performing dynamic mask scrambling processing on the legal network message based on a dynamic mask pool configured by the main control unit to obtain an encrypted network message, performing mask descrambling operation on the encrypted network message based on a local mask pool of the cryptographic unit to obtain a decrypted network message, and sending the decrypted network message to the user based on the network interface, so as to efficiently filter illegal messages entering the cryptographic device, reduce the risk of policy leakage, achieve efficient throughput of messages at the interface end, protect the security of message transfer and processing inside the cryptographic device, reduce the risk of malicious occupation of communication bandwidth, enhance the resistance of the cryptographic device to network attacks, prevent service interruption of the cryptographic device, and improve the service ability of the system where it is located.
[0035] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. Description of the Drawings
[0036] In the following, the present application will be described in more detail based on embodiments with reference to the accompanying drawings.
[0037] Figure 1 The schematic flowchart of a message processing method proposed in an embodiment of the present application is shown;
[0038] Figure 2 The schematic diagram of an application scenario which is a system composed of terminal cryptographic devices based on a network environment proposed in an embodiment of the present application is shown;
[0039] Figure 3 The schematic diagram of the internal structure of a cryptographic device and communication interaction proposed in an embodiment of the present application is shown;
[0040] Figure 4 The schematic diagram of a dynamic mask selection mechanism proposed in an embodiment of the present application is shown;
[0041] Figure 5 The schematic diagram of a symmetric operation of mask scrambling and mask descrambling proposed in an embodiment of the present application is shown;
[0042] Figure 6 The block diagram of an electronic device for executing the message processing method according to the embodiment of the present application proposed in the embodiment of the present application is shown;
[0043] Figure 7 The computer-readable storage medium for storing or carrying out the message processing method according to the embodiment of the present application proposed in the embodiment of the present application is shown. Detailed implementation manners
[0044] To make the objectives, technical solutions and advantages of the present invention clearer and more understandable, the present invention will be further described in detail below in combination with embodiments and the accompanying drawings. The illustrative embodiments and descriptions thereof of the present invention are only used to explain the present invention and are not intended to limit the present invention.
[0045] In the research of related technologies, for the deployment of terminal cryptographic devices in an intranet environment, there is a risk of network attacks by illegal users using illegal messages or defective messages, etc.
[0046] The present invention adopts a method combining dynamic mask scrambling operation and real-time policy configuration to efficiently filter illegal messages entering the cryptographic device, reduce the risk of policy leakage, achieve high-efficiency throughput of messages at the interface end, protect the security of message transfer and processing inside the cryptographic device, reduce the risk of malicious occupation of communication bandwidth, enhance the resistance of the cryptographic device to network attacks, prevent service interruption of the cryptographic device, and improve the service ability for the system where it is located.
[0047] In response to the above problems, the applicant proposes the message processing method, electronic device, and storage medium provided in the embodiments of the present application to achieve efficient and flexible filtering of illegal messages, reduce the leakage of filtering policies, and reduce the internal processing overhead of the cryptographic device and the ineffective occupation of communication bandwidth. Among them, a message processing method will be described in detail in the subsequent embodiments.
[0048] The following introduces the application scenarios of the message processing method provided in the embodiments of the present application:
[0049] Please refer to Figure 1 , Figure 1 which is a schematic flowchart of a message processing method provided in the embodiments of the present application. In this embodiment, the message processing method can be applied to a system composed of terminal cryptographic devices based on a network environment as shown in Figure 2 and an electronic device 200 as shown in Figure 6 . Among them, the electronic device 200 can include one or more. Exemplarily, the electronic device can include a mobile terminal, a computer, a tablet, etc., and the present application does not limit it.
[0050] In Figure 2 , the system composed of terminal cryptographic devices consists of a user, a cryptographic device, a channel transceiver, etc. The data transmission process is as follows:
[0051] Sending end:
[0052] The cryptographic device A receives the message from the sending-end user, implements the filtering of illegal messages on the network interface, and performs service encryption processing on the legal messages.
[0053] The cryptographic device A sends the encrypted service message to the channel transceiver A, and transmits it to the peer through a wireless / wired channel.
[0054] Receiving end:
[0055] The channel transceiver B receives the information transmitted through the wireless / wired channel and sends it to the cryptographic device B.
[0056] The cryptographic device B performs decryption processing, illegal message filtering, and sends the decrypted service message to the receiving-end user B.
[0057] The cryptographic device is composed of an interface isolation unit (FPGA chip), a cryptographic unit (CPU chip), a main control unit (SOC chip), etc.
[0058] Among them, the illegal message filtering function is implemented by the interface isolation unit. Please refer to Figure 3The internal structure of a cryptographic device and a schematic diagram of communication interaction are shown. The interface isolation unit uses an FPGA chip, designs a high-speed clock and a concurrent processing mechanism, and its processing capacity is much greater than the network interface bandwidth, enabling efficient throughput of external interfaces and efficient operation of internal processed data.
[0059] The interface isolation unit implements conventional exception message filtering, dynamic policy exception message filtering, and dynamic mask scrambling operations.
[0060] Among them, the user-defined filtering policy issued by the main control unit to the interface isolation unit is protected by dynamic mask scrambling operations. The mask value is a random number generated by two noise source chips externally connected to the main control unit. The method for selecting the dynamic mask is as Figure 4 shown in a schematic diagram of a dynamic mask selection mechanism. After XOR operation, it passes five randomness tests (frequency test, serial test, poker test, run test, and autocorrelation test). Each time it is used, a new mask value is generated and participates in the mask operation for configuring the policy data. The mask value is sent along with the configured policy data and is not reused. Refer to Figure 5 , Figure 5 This is a schematic diagram of symmetric operations for mask scrambling and mask descrambling shown in this application. The mask scrambling operation and the mask descrambling operation adopt a symmetric operation mechanism.
[0061] In Figure 2 , a one-packet-one-mask mechanism is adopted between the interface isolation unit and the cryptographic unit to scramble the legitimate packets transmitted between chips. Each packet is scrambled with a different mask, which is obtained from the mask pool when used and discarded after use, to prevent the packet data information transmitted across chips from being illegally monitored and the filtering policy from being analyzed and leaked.
[0062] When the mask resources in the local mask pool are used up to 1 / 2, the interface isolation unit applies to the main control unit again to replenish half of the used mask pool to ensure the cyclic use of mask pool resources. The main control unit sends the same mask pool resources to the interface isolation unit and the cryptographic unit respectively, and maintains the synchronization of mask values through the mask group number.
[0063] Next, a detailed elaboration is made on the Figure 1 process shown. It is applied to Figure 2 a system composed of terminal cryptographic devices based on a network environment. The message processing method may include S110 to S150.
[0064] S110: Receive a network message sent by a user based on a network interface.
[0065] S120: Filter the network message based on the interface isolation unit to obtain a legitimate network message.
[0066] In some embodiments, the filtering process includes a preliminary filtering process and a custom filtering process, and S120 includes S121 to S122.
[0067] S121: Perform a preliminary filtering process on network packets based on the interface isolation unit to obtain the first network packet.
[0068] In this embodiment, the preliminary filtering process may include filtering of regular abnormal packets, including FCS checksum abnormal filtering, length abnormal filtering, Jumbo frame abnormal filtering, etc.
[0069] S122: Configure a filtering policy for the main control unit based on user requirements, and perform a custom filtering process on the first network packet according to the filtering policy to obtain a legal network packet.
[0070] In the embodiments of the present application, the custom filtering process is a type of dynamic policy abnormal packet filtering, and a hierarchical processing mechanism can be adopted, including illegal address filtering, illegal IP filtering, illegal port filtering, illegal packet type filtering, illegal packet content filtering, and other custom filtering policies. The specific filtering policy configuration values are formulated by the user according to the actual task usage requirements and are configurable in real time.
[0071] In this embodiment, the combination of the regular abnormal packet filtering and the custom dynamic filtering policy can effectively filter illegal packets. The dynamic filtering policy adopts a hierarchical design, and the filtering policy is customized according to different tasks, which has strong flexibility and pertinence.
[0072] Among them, in the present application, the interface isolation unit implements the isolation mechanism using a high-speed FPGA chip. The FPGA internally adopts a high-speed clock and a concurrent processing mechanism to adapt to the efficient filtering process of illegal packets at various interface rates, and has strong interface bandwidth adaptability and small interface processing time delay.
[0073] S130: Perform a dynamic mask scrambling process on the legal network packet based on the dynamic mask pool configured by the main control unit to obtain an encrypted network packet.
[0074] The interface isolation unit includes: a first local mask pool. S130 may include S131 to S132, where:
[0075] S131: Obtain a first mask value based on the first local mask pool.
[0076] S132: Perform a dynamic mask scrambling process on the legal network packet based on the first mask value to obtain an encrypted network packet.
[0077] S140: Perform a mask descrambling operation on the encrypted network packet based on the local mask pool of the password unit to obtain a decrypted network packet.
[0078] The password unit includes: a second local mask pool, and S140 may include S141 to S142, where:
[0079] S141: Obtain the corresponding second mask value from the local mask pool based on the mask group number in the internal protocol of the password unit.
[0080] S142: Perform mask descrambling operation on the data area of the encrypted network packet based on the second mask value.
[0081] In the above embodiment, by performing mask scrambling operation on the legitimate packets transmitted between the internal chips of the password device, it is prevented that the data transmitted across chips is illegally monitored and the packet filtering strategy is analyzed and leaked.
[0082] Considering that in order to reduce the risk of strategy leakage and enhance the resistance of the password device to network attacks.
[0083] In some embodiments, it further includes: The packet processing method further includes: S210, where:
[0084] S210: Perform dynamic mask scrambling operation protection on the filtering strategy.
[0085] Wherein, the main control unit is further connected to a noise source chip, and S210 includes: S211 to S212, where:
[0086] S211: Perform exclusive OR operation on two noise source chips and then perform randomness detection to generate a random mask value, where the randomness detection includes: frequency test, serial test, poker test, run test and autocorrelation test.
[0087] S212: Send the random mask value along with the filtering strategy to protect the filtering strategy.
[0088] In this embodiment, by performing mask scrambling operation on the dynamically issued policy data, the mask value is a random number and is not reused, preventing the filtering strategy from being illegally obtained.
[0089] In some embodiments, the packet processing method further includes:
[0090] Send an application request for a dynamic mask pool to the main control unit;
[0091] Based on the application request, issue a dynamic mask pool to the interface isolation unit and the password unit.
[0092] In some embodiments, S211 includes S2111 to S2113, where:
[0093] S2111: Read the first detection data of one noise source chip and read the second detection data of another noise source chip.
[0094] S2112: Perform an exclusive OR operation on the first detection data and the second detection data to obtain a random mask value.
[0095] S2113: In the case where the random mask value does not meet any of the randomness detection items, an error alarm is given.
[0096] In this embodiment, the mask value is a random number, and a corresponding warning method is set to enable the user to confirm whether the filtering policy meets the requirements.
[0097] In this application, network interface isolation is implemented based on a high-speed FPGA chip. By combining the dynamic mask scrambling operation and the real-time filtering policy configuration for the network packets received by the cryptographic device, the filtering policy can be flexibly configured, enabling the cryptographic device to efficiently filter illegal packets, protecting the security of the legitimate packets during their transfer and processing inside the cryptographic device, reducing the internal processing overhead of the cryptographic device, preventing the communication bandwidth from being occupied invalidly, enhancing the resistance of the cryptographic device to network attacks. By using the method of combining the dynamic mask scrambling operation and the real-time policy configuration, illegal packets entering the cryptographic device are efficiently filtered, and the risk of policy leakage is reduced.
[0098] Exemplarily, as shown in the respective data transmission identifiers in Figure 2 :
[0099] The exemplary implementation process of this application is as follows:
[0100] Task preparation stage:
[0101] ① The main control unit formulates a user-defined real-time dynamic filtering policy according to the task requirements.
[0102] ② The main control unit performs mask scrambling processing on the configured policy data to prevent the filtering policy from being illegally obtained, and the mask value is synchronously sent to the interface isolation unit along with the configured policy.
[0103] ③ The interface isolation unit uses the configured policy after performing mask descrambling processing.
[0104] ④ The interface isolation unit requests a dynamic mask pool from the main control unit.
[0105] ⑤ The main control unit sends the dynamic mask pool data to the interface isolation unit and the cryptographic unit. The depth of the mask pool is dynamically configurable, with a default of 8K bytes. When 1 / 2 of the local mask pool mask resources are used, the interface isolation unit requests the main control unit to supplement the mask pool data again to ensure the cyclic use of the mask pool resources.
[0106] Task execution stage:
[0107] ⑥ The user sends network packets to the cryptographic device, including user legitimate packets and possible illegal packets.
[0108] ⑦The interface isolation unit receives packets through a network interface.
[0109] ⑧The interface isolation unit adopts a two - stage filtering mechanism. The first - stage filtering is for regular abnormal packet filtering, including FCS checksum abnormal filtering, length abnormal filtering, Jumbo frame abnormal filtering, etc. The packets after the first - stage filtering are transmitted to the subsequent stage for secondary filtering.
[0110] ⑨The secondary filtering of the interface isolation unit is an abnormal packet filtering policy based on user configuration, including illegal address filtering, illegal IP filtering, illegal port filtering, illegal packet type filtering, illegal packet content filtering, and other custom filtering policies, which are determined by the filtering policy configuration value in the task preparation stage. The configured policy can be dynamically changed in real - time according to task requirements. The legal packets after the secondary filtering are transmitted to the subsequent stage for dynamic mask scrambling processing of the packet content.
[0111] ⑩The interface isolation unit obtains a mask value from the local mask pool, performs a packet mask scrambling operation on the data area of the legal packet, and then sends it to the cipher unit for processing through an internal protocol (including the mask group number).
[0112] The cipher unit obtains the corresponding mask value from the local mask pool according to the mask group number in the internal protocol, and performs a mask descrambling operation on the data area of the legal packet.
[0113] The cipher unit parses the protocol fields of the packet. Illegal packets with incorrect protocol fields are discarded, and legal packets with correct protocol fields are subjected to encryption and decryption operations.
[0114] The interface isolation unit sends the packet after encryption and decryption processing to the user.
[0115] By combining dynamic mask scrambling and real - time policy configuration, it is possible to reduce the internal processing overhead of the cipher device and the ineffective occupation of communication bandwidth, reduce the leakage of filtering policies, enhance the resistance of the cipher device to network attacks, and reduce the risk of malicious occupation of communication bandwidth.
[0116] Please refer to Figure 6 , Figure 6 FIG. 200 is a structural block diagram of an electronic device 200 that can execute the above - mentioned packet processing method provided by an embodiment of the present application. The electronic device 200 can be a smart phone, a tablet computer, a computer, or a portable computer, etc.
[0117] The electronic device 200 further includes a processor 202 and a memory 204. Among them, the memory 204 stores a program that can execute the content in the foregoing embodiment, and the processor 202 can execute the program stored in the memory 204.
[0118] Among them, the processor 202 may include one or more cores for processing data and a message matrix unit. The processor 202 connects various parts within the entire electronic device 200 through various interfaces and circuits. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 204, and by invoking the data stored in the memory 204, it performs various functions of the electronic device 200 and processes data. Optionally, the processor 202 may be implemented in at least one hardware form of digital signal processing (DSP), field-programmable gate array (FPGA), or programmable logic array (PLA). The processor 202 may integrate a combination of one or several of a central processing unit (CPU), a graphics processing unit (GPU), and a modem decoder, etc. Among them, the CPU mainly processes the operating system, user interface, application programs, etc.; the GPU is responsible for rendering and drawing the display content; the modem is used to process wireless communications. It can be understood that the above-mentioned modem decoder may not be integrated into the processor and may be implemented separately through a communication chip.
[0119] The memory 204 may include a random access memory (RAM) and may also include a read-only memory. The memory 204 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 204 may include a program storage area and a data storage area. The program storage area may store instructions for implementing the operating system, instructions for implementing at least one function (such as instructions for a user to obtain a random number), instructions for implementing the following various method embodiments, etc. The data storage area may also store data created during the use of the terminal (such as random numbers), etc.
[0120] The electronic device 200 may further include a network module and a screen. The network module is used to receive and send electromagnetic waves, implement the mutual conversion between electromagnetic waves and electrical signals, so as to communicate with a communication network or other devices, such as communicating with an audio playback device. The network module may include various existing circuit elements for performing these functions, such as antennas, radio frequency transceivers, digital signal processors, encryption / decryption chips, subscriber identity module (SIM) cards, memories, and so on. The network module can communicate with various networks such as the Internet, enterprise intranets, wireless networks or communicate with other devices through a wireless network. The above-mentioned wireless network may include a cellular phone network, a wireless local area network or a metropolitan area network. The screen can display interface content and perform data interaction.
[0121] Please refer to Figure 7 , Figure 7 which shows a structural block diagram of a computer-readable storage medium provided by an embodiment of the present application. Program code 410 is stored in the computer-readable storage medium 400, and the program code 410 can be called by a processor to execute the method described in the above method embodiment.
[0122] The computer-readable storage medium 400 may be an electronic memory such as a flash memory, EEPROM (electrically erasable programmable read-only memory), EPROM, hard disk or ROM. Optionally, the computer-readable storage medium includes a non-transitory computer-readable storage medium. The computer-readable storage medium 400 has a storage space for the program code 410 that executes any method step in the above method. These program codes 410 can be read out from or written into one or more computer program products. The program code 410 can be compressed in an appropriate form, for example.
[0123] An embodiment of the present application also provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the message processing method described in the above various optional implementation manners.
[0124] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A message processing method, characterized in that: Applied to a cryptographic device, the cryptographic device comprises: an interface isolation unit, a main control unit and a cryptographic unit, the interface isolation unit is connected to a network interface, and the message processing method comprises: Receiving a network message sent by a user based on the network interface; Filtering the network message based on the interface isolation unit to obtain a legitimate network message; Performing dynamic mask scrambling processing on the legitimate network message based on the dynamic mask pool configured by the main control unit to obtain an encrypted network message; Performing a mask descrambling operation on the encrypted network message based on the local mask pool of the cryptographic unit to obtain a decrypted network message; The decrypted network message is sent to the user based on the network interface.
2. A message processing method according to claim 1, characterized in that: The filtering process includes preliminary filtering process and custom filtering process, and the filtering process based on the interface isolation unit on the network message to obtain a legitimate network message includes: Performing preliminary filtering processing on the network message based on the interface isolation unit to obtain a first network message; A filtering policy is configured for the main control unit based on user requirements, and a custom filtering process is performed on the first network message according to the filtering policy to obtain a legal network message.
3. A message processing method according to claim 2, characterized in that: The message processing method further includes: The filtering strategy is protected by a dynamic mask scrambling operation.
4. A message processing method according to claim 3, characterized in that: The main control unit is also connected to a noise source chip, and the dynamic mask scrambling operation protection for the filtering strategy includes: After performing an XOR operation on the two noise source chips, a randomness test is performed to generate a random mask value, wherein the randomness test includes: frequency test, sequence even test, poker test, run test and autocorrelation test; The random mask value is sent down along with the filtering policy to protect the filtering policy.
5. A message processing method according to claim 1, characterized in that: The message processing method further includes: Sending a dynamic mask pool application request to the main control unit; A dynamic mask pool is issued to the interface isolation unit and the cryptographic unit based on the application request.
6. A message processing method according to claim 1, characterized in that: The interface isolation unit includes: a first local mask pool, the dynamic mask pool configured based on the main control unit performs dynamic mask scrambling processing on the legal network message to obtain an encrypted network message, including: Obtaining a first mask value based on a first local mask pool; The legal network message is subjected to dynamic mask scrambling processing based on the first mask value to obtain an encrypted network message.
7. A message processing method according to claim 6, characterized in that: The cryptographic unit includes: a second local mask pool, and the local mask pool based on the cryptographic unit performs a mask descrambling operation on the encrypted network message to obtain a decrypted network message, including: Obtaining a corresponding second mask value from a local mask pool based on a mask group number in the internal protocol of the cryptographic unit; A mask descrambling operation is performed on the data area of the encrypted network message based on the second mask value.
8. A message processing method according to claim 4, characterized in that: The step of performing an XOR operation on the two noise source chips and then using randomness detection to generate a random mask value includes: Reading first detection data of one of the noise source chips, and reading second detection data of another of the noise source chips; Performing a data XOR operation based on the first detection data and the second detection data to obtain a random mask value; When the random mask value does not satisfy any item in the randomness detection, an error alarm is issued.
9. An electronic device, characterized in that: The electronic device includes a memory and a processor, the memory stores a program code that can be run on the processor, and when the program code is executed by the processor, a message processing method as described in any one of claims 1-8 is implemented.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores program codes, and the program codes can be called by one or more processors to execute a message processing method as described in any one of claims 1-8.