Distributed firewall method, system and device and storage medium thereof
By building a multi-layer system architecture in a distributed firewall and using encryption algorithms and smart contracts to control user access, the problem of management difficulty and performance bottlenecks of distributed firewall in complex management environments is solved, and efficient information security management and performance optimization are achieved.
Patent Information
- Application Number
- CN202510353476.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-25
- Publication Date
- 2025-06-24
AI Technical Summary
Existing distributed firewalls are difficult to effectively manage policies, log collection and monitoring when facing complex management environments of large organizations, and may lead to performance bottlenecks in high traffic environments.
It adopts a multi-layer system architecture, including user access layer, encryption layer, information storage layer and blank return layer, and uses encryption algorithms and smart contracts to control user access rights and encrypt data, and configures transmission security protocols to ensure the security of data transmission.
While ensuring information security, it reduces management difficulty, improves management capabilities in complex environments, and saves server performance.
Smart Images

Figure CN120200807A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and particularly to a distributed firewall method, system, device and its storage medium. Background Art
[0002] With the rapid development of network technology, more and more organizations use the network to achieve personnel management, product sales, business consulting, etc. To implement the above functions, each organization needs to build multiple servers. To improve the network information security within the organization, it is necessary to build a firewall to protect the information. There are mainly three types of firewalls: hardware firewall, software firewall, and distributed firewall. Among them, the distributed firewall has better overall security, finer-grained control, and reduces the risk of single-point failure compared to traditional firewalls.
[0003] However, in the working environment of large organizations, the policy management, log collection, and monitoring of distributed firewalls may involve thousands of nodes, making it difficult to manage. At the same time, in a high-traffic environment, the security processing on each node may lead to performance bottlenecks, further increasing the management difficulty.
[0004] Therefore, there is a need for a firewall that can handle complex management environments. Summary of the Invention
[0005] The main object of the present invention is to provide a distributed firewall method, aiming to solve the problem that it is difficult to handle complex management environments in the prior art.
[0006] To achieve the above object, the present invention proposes a distributed firewall method, which includes the following steps:
[0007] Build a multi-layer system architecture, the multi-layer system architecture includes a user access layer, an encryption layer, an information storage layer, and a blank return layer, and build a distributed firewall policy in the information storage layer;
[0008] Build an encryption algorithm in the encryption layer. When a user accesses, obtain the user information and generate a private key through the encryption algorithm. The encryption algorithm synchronously matches the private key and randomly generates a public key and transmits the public key to the information storage layer;
[0009] Judge the user access permission. When a user accesses, the user access layer transmits the access request to the encryption layer. The encryption layer compares the user's private key with the public key to judge whether the user has access authorization. If so, allow the user to access. If not, send the user access request to the blank return layer;
[0010] Define the status of the accessing user, configure a smart contract in the information storage layer, and control the user's access through the smart contract;
[0011] Configure a transmission security protocol, configure a transmission security protocol in the information storage layer, and encrypt the transmission signals from the encryption layer to the information storage layer and / or from the information storage layer to the blank return layer.
[0012] Furthermore, the step of constructing an encryption algorithm in the encryption layer, when a user accesses, obtaining user information and generating a private key through the encryption algorithm, and the encryption algorithm synchronously matching the private key to randomly generate a public key and transmitting the public key to the information storage layer includes:
[0013] When a user requests access for the first time, obtain user information and transmit the access request from the user access layer to the encryption layer. The encryption layer generates a random code as the public key and stores the public key in the information storage layer. Then, the encryption layer randomly generates and distributes a private key to the user.
[0014] When a user accesses for the second time, the user inputs the private key. The encryption layer decrypts the private key and compares it with the public key in the information storage layer. After the comparison passes, the user information is encrypted and stored, and compared with the multiple login information to determine whether the user has access rights.
[0015] Furthermore, the step of constructing an encryption algorithm in the encryption layer, when a user accesses, obtaining user information and generating a private key through the encryption algorithm, and the encryption algorithm synchronously matching the private key to randomly generate a public key and transmitting the public key to the information storage layer, further includes:
[0016] Generate a Blowfish algorithm key and store the Blowfish algorithm key in the information storage layer;
[0017] Generate an 8-byte random initialization vector IV and store the random initialization vector IV together with the user information in the information storage layer;
[0018] Divide the user information and the user public key into blocks, with each block being 8 bytes in size. Then, apply the initialized Blowfish algorithm and CBC mode to each data block for encryption to generate ciphertext data.
[0019] Combine the ciphertext data and the random initialization vector IV to obtain an encrypted data packet;
[0020] Upload the encrypted data packet to the IPFS system and obtain the content identifier CID returned by IPFS to encrypt the user private key and user information stored in the information storage layer.
[0021] Furthermore, the step of defining the status of the accessing user, configuring a smart contract in the information storage layer, and controlling the user's access through the smart contract includes:
[0022] When a user requests access for the first time, a corresponding role is configured for the user, the role name, read permission, and write permission of the visitor are defined, and the role information of the user is transmitted to the information storage layer through an encryption algorithm;
[0023] Define a role management contract in the user layer, allowing a specific role to be assigned to a user and / or revoking a specific role of a user;
[0024] Define a role management process in the user layer. For a corresponding access application, a role assignment process is defined accordingly, which is responsible for initiating and managing the entire role assignment process, as well as an auxiliary process for a corresponding role assignment process.
[0025] Furthermore, the steps of defining the status of the access user, configuring a smart contract in the information storage layer, and controlling the user's access through the smart contract include:
[0026] Obtain user information of those who have been offline for more than three days and log in with abnormal behaviors such as abnormal IP addresses and machine codes, mark them as abnormal, and prohibit the access rights of abnormal users;
[0027] When a user has been offline for more than three days and has normal behaviors such as normal IP addresses and machine codes, mark the user information as pending to be restored to normal and restrict the access rights of users pending to be restored to normal;
[0028] When a user maintains continuous login or continuously logs in for three days in a pending-to-be-restored-normal state, mark the user information as normal and provide the access rights of normal users.
[0029] The present invention also proposes a distributed firewall system, including:
[0030] A central management server module, used to formulate and manage security policies, distribute the security policies, summarize and analyze the security logs after distribution, and regularly organize them into security reports for reporting to the administrator;
[0031] A network firewall module, used to separate the internal network from the external network and provide security protection for all internal networks;
[0032] A hosted host module, used to install a firewall and configure the required security policies according to relevant settings;
[0033] A host firewall module, used to be responsible for the implementation of security policies and protect the security of the hosted host module.
[0034] The present invention also proposes a distributed firewall device, which includes: a memory, a processor, and a data migration program stored on the memory and executable on the processor. The data migration program is configured to implement the data migration method described in any one of the above technical solutions
[0035] The present invention also provides a storage medium, which is a computer-readable storage medium. A computer program is stored on the storage medium. When the computer program is executed by a processor, it performs the steps of the distributed firewall method described in any one of the above technical solutions.
[0036] The present invention uses a distributed firewall with a multi-layer system architecture to protect information security. By cooperating with each other among the user access layer, the encryption layer, the information storage layer, and the blank return layer, and constructing the security policy of the distributed firewall in the multi-layer system architecture, multiple verifications and encryptions are performed during the user access process, isolating the user access request from the information obtained by the user. While ensuring security, it also reduces the management difficulty, enabling the present invention to still have a high management ability in the face of complex environments and saving server performance. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to the processes shown in these drawings.
[0038] Figure 1 It is a schematic flowchart of the first embodiment of the distributed firewall method of the present invention;
[0039] Figure 2 It is a schematic flowchart of the second embodiment of the distributed firewall method of the present invention;
[0040] Figure 3 It is a schematic flowchart of the third embodiment of the distributed firewall method of the present invention;
[0041] Figure 4 It is a schematic diagram of the module structure of an embodiment in the distributed firewall system of the present invention;
[0042] Figure 5 It is a schematic diagram of the device structure of the hardware operating environment designed by the distributed firewall method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0043] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0044] It should be noted that all the directional indications (such as up, down, left, right, front, back...) in the embodiments of the present invention are only used to explain the relative positional relationship, movement conditions, etc. between components in a specific posture (as shown in the attached drawings). If this specific posture changes, the directional indications will also change accordingly.
[0045] In addition, the descriptions involving "first", "second", etc. in the present invention are only for descriptive purposes, and cannot be understood as indicating or implying their relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include at least one such feature. In addition, the technical solutions between various embodiments can be combined with each other, but it must be based on the fact that those skilled in the art can implement it. When the combination of technical solutions conflicts with each other or cannot be implemented, it should be considered that such a combination of technical solutions does not exist and is not within the protection scope required by the present invention.
[0046] It can be understood that a distributed firewall is an internal firewall. Its working principle is to directly embed security services into the network structure. Especially in each host or virtual environment, the distributed firewall has the advantage of decentralization, can finely implement security policies, and avoid the low anti-risk ability caused by guiding all traffic through the central firewall. However, the distributed firewall has the problem of difficult management caused by frequent interaction of complex multi-source information.
[0047] Based on this, referring to Figures 1-5 , the embodiments of the present application provide a distributed firewall method.
[0048] A distributed firewall method provided by the present invention specifically includes the following steps:
[0049] S10. Build a multi-layer system architecture, where the multi-layer system architecture includes a user access layer, an encryption layer, an information storage layer, and a blank return layer, and build a distributed firewall policy in the information storage layer;
[0050] S20. Build an encryption algorithm in the encryption layer. When a user accesses, obtain user information and generate a private key through the encryption algorithm. The encryption algorithm synchronously matches the private key to randomly generate a public key and transmits the public key to the information storage layer;
[0051] S30. Judge the user access permission. When a user accesses, the user access layer transmits the access request to the encryption layer. The encryption layer compares the user's private key with the public key to judge whether the user has access authorization. If so, allow the user to access. If not, send the user access request to the blank return layer;
[0052] S40. Define the status of the accessing user, configure a smart contract in the information storage layer, and control the user's access through the smart contract;
[0053] S50. Configure a transport security protocol. Configure a transport security protocol in the information storage layer to encrypt the transmission signals from the encryption layer to the information storage layer and / or from the information storage layer to the blank return layer.
[0054] It can be understood that traditional firewalls rely on controlling the entry point to operate. That is, each user on one side of the entry point of the traditional firewall is a trusted entity, while any user on the other side is an untrusted entity. The working principle of a distributed firewall is to only allow basic traffic to enter the host it protects and prohibit other types of traffic to prevent unnecessary intrusions. The fact that the host side of the distributed firewall does not provide any management control for the administrator to manage security policies, and the host side distributes traffic according to the security policies configured and implemented by it.
[0055] In the first embodiment, a distributed firewall is constructed by setting up a multi-layer system architecture including a user access layer, an encryption layer, an information storage layer, and a blank return layer on a managed host, and the security policies of the distributed firewall are configured in the information storage layer to protect the information that needs to be protected. Specifically, when a user needs to access, an access request is sent through the user access layer. The access request is transmitted to the encryption layer, and the encryption layer encrypts the access information of the accessing user, isolating the user's access behavior and the access request from the return of internal data, preventing the user from attacking the data stored in the firewall through malicious intrusion methods such as Trojans. Then, the smart contract and related information stored in the encryption layer and the information storage layer are used to verify the user's status and judge the user's access rights. When the accessing user passes the verification completely, the data that can be written or read within the user's request range is encrypted again through the transport security protocol of the encryption layer before being output to the user access layer. Re-encrypting the output data through the encryption layer can further improve the security of the data. When the accessing user does not pass the verification completely, the user's access request is sent to the blank return layer, and the traffic is dispersed through the blank return layer and multiple nodes of the distributed firewall to prevent malicious intrusion users from attacking the distributed firewall through DDoS attacks or other malicious intrusion methods.
[0056] In another embodiment, the blank return layer can also be provided with a chronological list. Even if the accessing user passes the verification completely, the access request also comes to the blank return layer and is added to the chronological list for queuing, and it is restricted that only a limited number of users can complete the access request within a certain time threshold, preventing traffic congestion caused by a large number of users querying the database simultaneously at the same time.
[0057] In this embodiment, the steps of constructing an encryption algorithm in the encryption layer, obtaining user information when a user accesses, and generating a private key through the encryption algorithm, and synchronously matching the encryption algorithm with the private key to randomly generate a public key and transmit the public key to the information storage layer include:
[0058] S21. When a user requests access for the first time, obtain the user information and transmit the access request from the user access layer to the encryption layer. The encryption layer generates a random code as the public key, stores the public key in the information storage layer, and then randomly generates and distributes a private key to the user;
[0059] S22. When the user accesses for the second time, the user inputs the private key. The encryption layer decrypts the private key and compares it with the public key in the information storage layer. After the comparison passes, the user information is encrypted and stored, and compared with the multiple login information to determine whether the user has the access permission.
[0060] S23. Generate a Blowfish algorithm key and store the Blowfish algorithm key in the information storage layer;
[0061] S24. Generate an 8-byte random initialization vector IV and store the random initialization vector IV and the user information together in the information storage layer;
[0062] S25. Divide the user information and the user public key into blocks, with each block being 8 bytes in size, and then apply the initialized Blowfish algorithm and the CBC mode to each data block for encryption to generate ciphertext data;
[0063] S26. Combine the ciphertext data and the random initialization vector IV to obtain an encrypted data packet;
[0064] S27. Upload the encrypted data packet to the IPFS system, and obtain the content identifier CID returned by IPFS to encrypt the user private key and the user information stored in the information storage layer.
[0065] It is understandable that the Blowfish algorithm is a symmetric key block cipher algorithm with the effect of variable key length (32 to 448 bits) and high security and speed of the algorithm. The CBC (Cipher Block Chaining) mode is an encryption mode in cryptography. By dividing the plaintext into multiple "blocks" and using a key and an initial vector (IV) to encrypt each "block", the encryption of each "block" depends not only on the current plaintext "block" obtained, but also on all previous plaintext "blocks" and ciphertext "blocks". In the CBC mode, each plaintext "block" will perform an exclusive OR (XOR) operation with the previous ciphertext "block" before encryption. The first plaintext "block" performs an XOR operation with the initial vector (IV). The IV is used for data recovery during the decryption process. The IV value is randomly generated during the encryption process and stored together with the ciphertext "block". The encrypted data format is represented as: ciphertext "block" 1 + IV1 + ciphertext "block" 2 + IV2 +... + ciphertext "block" N + IVN.
[0066] In the second embodiment, when a user requests access, the distributed firewall method proposed by the present invention records the information of the accessing user, verifies the access permission of the user and distributes the corresponding role of the user. The information of the user includes information such as IP address, access time, accessed page, Cookie data, etc. A role is an abstract definition corresponding to a set of permissions in the system. The number of roles can be multiple. Any one of the roles corresponds to a set of independent permissions. The permissions limit the data range that the role can access and the operations that can be performed. And each user can bind at least one role to obtain multiple permissions. After the user passes the information authentication, the role assigned by the system is obtained, and the permissions bound to the role are used to access the corresponding data and / or perform operations.
[0067] In the second implementation, a 256-bit key is selected for encryption. When each user logs in for the first time, the encryption layer generates a unique encryption key as the private key through a random number generator (RNG). The private key is bound to the user information and is distributed and managed by the key management module provided in the encryption layer and stored in the secure key library provided in the information storage layer. After the user information, user private key, user public key and other data are integrated, they are cut into several "blocks" of 8 bytes in size, and then encrypted through the CBC mode, and a corresponding initial vector IV is generated for each "block". After encrypting the user information, user private key and user public key, they are stored in the information storage layer. When the user logs in next time, the encryption layer calls the corresponding data from the information storage layer and decrypts it, and compares the current user information with the previous user information to determine whether the current user has access permission.
[0068] It can be understood that the definition of IPFS (InterPlanetary File System) is a decentralized file storage system that stores and shares files through content addressing. Files are distributedly stored on multiple nodes and backed up by multiple nodes, and files are accessed through content hash values, avoiding the single point of failure of centralized storage, improving storage and retrieval efficiency, and enhancing data persistence and reliability. In another embodiment, IPFS generates a unique content hash value (CID) for each data "block". After the data "block" is uploaded to the IPFS network, the system records the CID of each data "block" and combines these CIDs into a Merkle tree. The root hash value (rootCID) of the Merkle tree is used as the unique identifier of the entire data file.
[0069] In this embodiment, the steps of defining the state of the accessing user, configuring a smart contract in the information storage layer, and controlling the user's access through the smart contract include:
[0070] S41. When a user requests access for the first time, assign a corresponding role to the user, define the role name, read permission, and write permission of the visitor, and transmit the user's role information to the information storage layer through an encryption algorithm;
[0071] S42. Define a role management contract in the user layer that allows a specific role to be assigned to a user and / or revoke a specific role of a user;
[0072] S43. Define a role management process in the user layer. For a corresponding access application, define a role assignment process accordingly, which is responsible for initiating and managing the entire role assignment process, as well as an auxiliary process for a corresponding role assignment process.
[0073] S44. Obtain the user information of those who have been offline for more than three days and log in with abnormal behaviors such as abnormal IP addresses and machine codes, mark them as abnormal, and prohibit the access rights of abnormal users;
[0074] S45. When a user has been offline for more than three days and has normal behaviors such as normal IP addresses and machine codes, mark the user information as pending recovery to normal and restrict the access rights of users pending recovery to normal;
[0075] S46. When a user maintains continuous login or continuously logs in for three days in the pending recovery to normal state, mark the user information as normal and provide the access rights of normal users.
[0076] In the third embodiment, the system is capable of managing role management contracts. When a user logs in, the system assigns the user information to one or more specific roles correspondingly, and is also able to verify role assignment and revocation transactions. During the role assignment process, the system initiates an anonymous transaction and generates an anonymous object, which is used to complete the anonymous transaction. The anonymous transaction is used to obtain the intranet data of the distributed firewall. The system starts an initiation process by calling, and this initiation process receives the roles to be assigned and the information of the users to be assigned to the corresponding roles, and also generates an associated object, which tracks the initiation process.
[0077] In another embodiment, the threshold of the number of offline days can be adjusted according to the needs of the administrator.
[0078] As Figure 4 shown, the present invention also proposes a distributed firewall system, including:
[0079] A central management server module 10, which is used to formulate and manage security policies, distribute the security policies, summarize and analyze the security logs after distribution, and regularly organize them into security reports for reporting to the administrator;
[0080] A network firewall module 20, which is used to separate the intranet from the extranet and provide security protection for all intranets;
[0081] A managed host module 30, which is used to install a firewall and configure the required security policies according to relevant settings;
[0082] A host firewall module 40, which is used to be responsible for the implementation of security policies and protect the security of the managed host module.
[0083] The distributed firewall system provided by the present application adopts the distributed firewall method in the above embodiment and can solve the proposed technical problems. Compared with the prior art, the beneficial effects of the distributed firewall system provided by the present application are the same as those of the distributed firewall method provided by the above embodiment, and other technical features in the distributed firewall system are the same as those disclosed in the method of the above embodiment, and will not be elaborated here.
[0084] The present invention can also relate to a distributed firewall device, and this device includes:
[0085] At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the distributed firewall method in the first embodiment above.
[0086] The distributed firewall device in the embodiments of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistant), PADs (Portable Application Description: tablet computers), PMPs (Portable Media Player: portable multimedia players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. The distributed firewall device disclosed above is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.
[0087] As Figure 5 shown, the distributed firewall device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM: Read Only Memory) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the distributed firewall device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the distributed firewall device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a distributed firewall device having various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be alternatively implemented or had.
[0088] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product that includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device, or installed from a storage device 1003, or installed from a ROM 1002. When the computer program is executed by a processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0089] The distributed firewall device provided by the present application adopts the distributed firewall method in the above embodiments and can solve the technical problems that are difficult to handle by the distributed firewall in the face of a complex management environment. Compared with the prior art, the beneficial effects of the distributed firewall device provided by the present application are the same as those of the distributed firewall method provided by the above embodiments, and other technical features in the distributed firewall device are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.
[0090] The present invention also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it performs the steps of the distributed firewall method in any one of the above technical solutions.
[0091] The present invention also proposes a computer-readable storage medium with computer-readable program instructions (i.e., a computer program) stored thereon, and the computer-readable program instructions are used to execute the distributed firewall method in the above embodiments.
[0092] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0093] The above computer-readable storage medium can be included in a distributed firewall device; or it can exist separately and not be assembled into the distributed firewall device.
[0094] It should be understood that the various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0095] As described above, this is only the specific implementation manner of the present invention, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed by this application can easily think of changes or substitutions, which should all be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0096] Combining all the above embodiments, the present invention provides a distributed firewall method, system, device and its storage medium. The present invention uses a distributed firewall with a multi-layer system architecture to protect information security. By cooperating with each other among the user access layer, encryption layer, information storage layer and blank return layer, and constructing security policies of the distributed firewall in the multi-layer system architecture. When a user logs in for the first time, a private key and a public key are generated through the encryption layer, and the isolation of information data is achieved under the action of corresponding encryption policies and the blank layer. The present invention realizes multiple verifications and encryptions during the user access process, isolates the user access request from the information obtained by the user, reduces the management difficulty while ensuring security, enables the present invention to still have a high management ability in the face of complex environments, and saves server performance.
[0097] The above are only the preferred embodiments of the present invention, and do not limit the patent scope of the present invention accordingly. Any equivalent structural transformation made by using the content of the specification and drawings of the present invention under the inventive concept of the present invention, or direct / indirect application in other related technical fields, is included in the patent protection scope of the present invention.
Claims
1. A distributed firewall method, characterized in that: The following steps are involved: Constructing a multi-layer system architecture, the multi-layer system architecture includes a user access layer, an encryption layer, an information storage layer, and a blank return layer, and constructing a distributed firewall strategy in the information storage layer; Construct an encryption algorithm in the encryption layer. When a user accesses the information, the user information is obtained and a private key is generated through the encryption algorithm. The encryption algorithm synchronously matches the private key to randomly generate a public key and transmit the public key to the information storage layer. Determine the user's access rights. When the user accesses, the user access layer transmits the access request to the encryption layer. The encryption layer compares the user's private key with the public key to determine whether the user has access authorization. If so, the user is allowed to access. If not, the user access request is transmitted to the blank return layer. Define the status of access users, configure smart contracts in the information storage layer, and control user access through smart contracts; Configure the transmission security protocol, configure the transmission security protocol in the information storage layer, and encrypt the transmission signal from the encryption layer to the information storage layer and / or from the information storage layer to the blank return layer.
2. The distributed firewall method according to claim 1, characterized in that: The steps of constructing an encryption algorithm in the encryption layer, obtaining user information and generating a private key through the encryption algorithm when a user accesses the information, and the encryption algorithm synchronously matching the private key to randomly generate a public key and transmitting the public key to the information storage layer include: When a user requests access for the first time, the user information is obtained and the access request is transmitted from the user access layer to the encryption layer. The encryption layer generates a random code as a public key and stores the public key in the information storage layer. The encryption layer then randomly generates and distributes a private key to the user. When the user accesses the site for the second time, the user enters the private key. The encryption layer decrypts the private key and compares it with the public key in the information storage layer. After the comparison, the user information is encrypted and stored, and compared with multiple login information to determine whether the user has access rights.
3. The distributed firewall method according to claim 2, characterized in that: The step of constructing an encryption algorithm in the encryption layer, obtaining user information and generating a private key through the encryption algorithm when the user accesses, and the encryption algorithm synchronously matching the private key to randomly generate a public key and transmit the public key to the information storage layer also includes: Generate a Blowfish algorithm key and store the Blowfish algorithm key in the information storage layer; Generate an 8-byte random initialization vector IV, and store the random initialization vector IV and user information together in the information storage layer; Divide the user information and user public key into blocks, each block is 8 bytes in size, and then encrypt each data block using the initialized Blowfish algorithm and CBC mode to generate ciphertext data; Combining the ciphertext data with the random initialization vector IV to obtain an encrypted data packet; The encrypted data packet is uploaded to the IPFS system, and the content identifier CID returned by IPFS is obtained to encrypt the user private key and user information stored in the information storage layer.
4. The distributed firewall method according to claim 1, characterized in that: The steps of defining the state of the access user, configuring the smart contract in the information storage layer, and controlling the user's access through the smart contract include: When a user requests access for the first time, the user is assigned a corresponding role, the role name, read permission, and write permission of the visitor are defined, and the user's role information is transmitted to the information storage layer through an encryption algorithm; Defines the role management contract in the user layer, allowing a specific role to be assigned to a user and / or a specific role to be revoked from a user; Define the role management process in the user layer. For each access application, define a role allocation process accordingly. The process is responsible for initiating and managing the entire role allocation process, as well as an auxiliary process for the corresponding role allocation process.
5. The distributed firewall method according to claim 1, characterized in that: The steps of defining the state of the access user, configuring the smart contract in the information storage layer, and controlling the user's access through the smart contract include: Obtain information about users who have been offline for more than three days and logged in with abnormal IP addresses, machine codes, or other abnormal behaviors, and mark them as abnormal, and prohibit access rights for abnormal users; When a user is offline for more than three days and has normal behavior with a normal IP, machine code, etc., the user information will be marked as pending restoration, and the access rights of the user pending restoration will be restricted; When a user remains logged in continuously or logs in continuously for three days in a state waiting to be restored to normal, the user information is marked as normal and the normal user's access rights are provided.
6. A distributed firewall system, characterized in that: include: The central management server module is used to formulate and manage security policies, distribute security policies, summarize and analyze security logs after distribution, and regularly compile them into security reports for the administrator; Network firewall module, used to separate the internal network from the external network and provide security protection for all internal networks; Hosting module, used to install firewall and configure required security policies according to relevant settings; The host firewall module is responsible for implementing security policies and protecting the security of managed host modules.
7. A distributed firewall device, characterized in that: The device comprises: a memory, a processor, and a data migration program stored in the memory and executable on the processor, wherein the data migration program is configured to implement the data migration method according to any one of claims 1 to 5.
8. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the distributed firewall method according to any one of claims 1 to 5 are performed.